<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" pub_date="2012-02-14" nvd_xml_version="1.2" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2010-0001" published="2010-01-29" name="CVE-2010-0001" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT">RHSA-2010:0095</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=554418" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=554418</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1872" source="VUPEN">ADV-2010-1872</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1796" source="VUPEN">ADV-2010-1796</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0185" source="VUPEN" adv="1">ADV-2010-0185</ref>
      <ref url="http://www.ubuntu.com/usn/USN-889-1" source="UBUNTU">USN-889-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0061.html" source="REDHAT">RHSA-2010:0061</ref>
      <ref url="http://www.osvdb.org/61869" source="OSVDB">61869</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:152" source="MANDRIVA">MDVSA-2011:152</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:020" source="MANDRIVA">MDVSA-2010:020</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:019" source="MANDRIVA">MDVSA-2010:019</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2074" source="DEBIAN">DSA-2074</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1974" source="DEBIAN">DSA-1974</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securitytracker.com/id?1023490" source="SECTRACK">1023490</ref>
      <ref url="http://secunia.com/advisories/40689" source="SECUNIA">40689</ref>
      <ref url="http://secunia.com/advisories/40655" source="SECUNIA">40655</ref>
      <ref url="http://secunia.com/advisories/40551" source="SECUNIA">40551</ref>
      <ref url="http://secunia.com/advisories/38232" source="SECUNIA" adv="1">38232</ref>
      <ref url="http://secunia.com/advisories/38225" source="SECUNIA" adv="1">38225</ref>
      <ref url="http://secunia.com/advisories/38223" source="SECUNIA" adv="1">38223</ref>
      <ref url="http://secunia.com/advisories/38220" source="SECUNIA" adv="1">38220</ref>
      <ref url="http://savannah.gnu.org/forum/forum.php?forum_id=6153" source="CONFIRM">http://savannah.gnu.org/forum/forum.php?forum_id=6153</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7511" source="OVAL">oval:org.mitre.oval:def:7511</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10546" source="OVAL">oval:org.mitre.oval:def:10546</ref>
      <ref url="http://ncompress.sourceforge.net/#status" source="CONFIRM">http://ncompress.sourceforge.net/#status</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">HPSBMA02554</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">HPSBMA02554</ref>
      <ref url="http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f" source="CONFIRM">http://git.savannah.gnu.org/cgit/gzip.git/commit/?id=a3db5806d012082b9e25cc36d09f19cd736a468f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gzip">
        <vers num="1.2.4" />
        <vers num="1.2.4a" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers prev="1" num="1.3.13" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0002" published="2010-01-14" name="CVE-2010-0002" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:004" source="MANDRIVA" patch="1" adv="1">MDVSA-2010:004</ref>
      <ref url="https://qa.mandriva.com/show_bug.cgi?id=56882" source="CONFIRM">https://qa.mandriva.com/show_bug.cgi?id=56882</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="bash">
        <vers num="2.05" edition="b" />
        <vers num="3.0" />
        <vers num="3.2" />
        <vers num="3.2.48" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0003" published="2010-01-26" name="CVE-2010-0003" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="3.4" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0146.html" source="REDHAT">RHSA-2010:0146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=554578" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=554578</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/37724" source="BID">37724</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0147.html" source="REDHAT">RHSA-2010:0147</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/13/4" source="MLIST">[oss-security] 20100113 Re: CVE request - kernel: infoleak if print-fatal-signals=1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/12/1" source="MLIST">[oss-security] 20100112 CVE request - kernel: infoleak if print-fatal-signals=1</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://secunia.com/advisories/38333" source="SECUNIA" adv="1">38333</ref>
      <ref url="http://patchwork.kernel.org/patch/69752/" source="CONFIRM">http://patchwork.kernel.org/patch/69752/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10550" source="OVAL">oval:org.mitre.oval:def:10550</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE">SUSE-SA:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE">SUSE-SA:2010:010</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" source="FEDORA">FEDORA-2010-0919</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b45c6e76bc2c72f6426c14bed64fdcbc9bf37cb0" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b45c6e76bc2c72f6426c14bed64fdcbc9bf37cb0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="e1000">
        <vers num="5.2.22" />
        <vers num="5.2.30.1" />
        <vers num="5.2.52" />
        <vers num="5.3.19" />
        <vers num="5.4.11" />
        <vers num="5.5.4" />
        <vers num="5.6.10" />
        <vers num="5.6.10.1" />
        <vers num="5.7.6" />
        <vers num="6.0.54" />
        <vers num="6.0.60" />
        <vers num="6.1.16" />
        <vers num="6.2.15" />
        <vers num="6.3.9" />
        <vers num="7.0.33" />
        <vers num="7.0.41" />
        <vers num="7.1.9" />
        <vers num="7.2.7" />
        <vers num="7.2.9" />
        <vers num="7.3.15" />
        <vers num="7.3.20" />
        <vers num="7.4.27" />
        <vers prev="1" num="7.4.35" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0004" published="2010-01-29" name="CVE-2010-0004" modified="2010-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01464.html" source="FEDORA">FEDORA-2009-13634</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01421.html" source="FEDORA">FEDORA-2009-13610</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/14/4" source="MLIST">[oss-security] 20100114 Re: CVE Request: viewvc</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/13/5" source="MLIST">[oss-security] 20100113 Re: CVE Request: viewvc</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/11/2" source="MLIST">[oss-security] 20100111 CVE Request: viewvc</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300" source="CONFIRM">http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD" source="CONFIRM">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD</ref>
      <ref url="http://viewvc.tigris.org/source/browse/%2Acheckout%2A/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222" source="CONFIRM">http://viewvc.tigris.org/source/browse/*checkout*/viewvc/trunk/docs/release-notes/1.1.0.html?revision=2222</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewvc" name="viewvc">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0005" published="2010-01-29" name="CVE-2010-0005" modified="2010-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD" source="CONFIRM" patch="1">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2242&amp;r2=2313&amp;pathrev=HEAD</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01464.html" source="FEDORA">FEDORA-2009-13634</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01421.html" source="FEDORA">FEDORA-2009-13610</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/13/5" source="MLIST">[oss-security] 20100113 Re: CVE Request: viewvc</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/11/2" source="MLIST">[oss-security] 20100111 CVE Request: viewvc</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300" source="CONFIRM">http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2300</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewvc" name="viewvc">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0006" published="2010-01-26" name="CVE-2010-0006" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555217" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555217</ref>
      <ref url="http://www.securityfocus.com/bid/37810" source="BID">37810</ref>
      <ref url="http://www.osvdb.org/61876" source="OSVDB">61876</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/14/2" source="MLIST">[oss-security] 20100114 CVE-2010-0006 - kernel: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo()</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-0006" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-0006</ref>
      <ref url="http://secunia.com/advisories/38333" source="SECUNIA" adv="1">38333</ref>
      <ref url="http://secunia.com/advisories/38168" source="SECUNIA" adv="1">38168</ref>
      <ref url="http://marc.info/?l=linux-netdev&amp;m=126343325807340&amp;w=2" source="MLIST">[linux-netdev] 20100114 [PATCH]: ipv6: skb_dst() can be NULL in ipv6_hop_jumbo().</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE">SUSE-SA:2010:010</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" source="FEDORA">FEDORA-2010-0919</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2570a4f5428bcdb1077622342181755741e7fa60" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2570a4f5428bcdb1077622342181755741e7fa60</ref>
      <ref url="http://cert.fi/en/reports/2010/vulnerability341748.html" source="MISC">http://cert.fi/en/reports/2010/vulnerability341748.html</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=300951" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=300951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="e1000">
        <vers num="5.2.22" />
        <vers num="5.2.30.1" />
        <vers num="5.2.52" />
        <vers num="5.3.19" />
        <vers num="5.4.11" />
        <vers num="5.5.4" />
        <vers num="5.6.10" />
        <vers num="5.6.10.1" />
        <vers num="5.7.6" />
        <vers num="6.0.54" />
        <vers num="6.0.60" />
        <vers num="6.1.16" />
        <vers num="6.2.15" />
        <vers num="6.3.9" />
        <vers num="7.0.33" />
        <vers num="7.0.41" />
        <vers num="7.1.9" />
        <vers num="7.2.7" />
        <vers num="7.2.9" />
        <vers num="7.3.15" />
        <vers num="7.3.20" />
        <vers num="7.4.27" />
        <vers prev="1" num="7.4.35" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers prev="1" num="2.6.32.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0007" published="2010-01-19" name="CVE-2010-0007" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0109" source="VUPEN" patch="1" adv="1">ADV-2010-0109</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0146.html" source="REDHAT">RHSA-2010:0146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555238" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555238</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55602" source="XF">kernel-ebtables-security-bypass(55602)</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/37762" source="BID">37762</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0147.html" source="REDHAT">RHSA-2010:0147</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/14/3" source="MLIST">[oss-security] 20100114 Re: CVE Request: kernel ebtables perm check</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/14/1" source="MLIST">[oss-security] 20100113 CVE Request: kernel ebtables perm check</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:051" source="MANDRIVA">MDVSA-2011:051</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc4</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://secunia.com/advisories/38333" source="SECUNIA">38333</ref>
      <ref url="http://secunia.com/advisories/38296" source="SECUNIA">38296</ref>
      <ref url="http://secunia.com/advisories/38133" source="SECUNIA" adv="1">38133</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9630" source="OVAL">oval:org.mitre.oval:def:9630</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00007.html" source="SUSE">SUSE-SA:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE">SUSE-SA:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE">SUSE-SA:2010:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00008.html" source="SUSE">SUSE-SA:2010:007</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034250.html" source="FEDORA">FEDORA-2010-0919</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dce766af541f6605fa9889892c0280bab31c66ab" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=dce766af541f6605fa9889892c0280bab31c66ab</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0008" published="2010-03-19" name="CVE-2010-0008" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/17/2" source="MLIST" patch="1">[oss-security] 20100317 CVE-2010-0008 kernel: sctp remote denial of service</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ece25dfa0991f65c4e1d26beb1c3c45bda4239b8" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ece25dfa0991f65c4e1d26beb1c3c45bda4239b8</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0146.html" source="REDHAT">RHSA-2010:0146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555658" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555658</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0342.html" source="REDHAT">RHSA-2010:0342</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0147.html" source="REDHAT">RHSA-2010:0147</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA" adv="1">43315</ref>
      <ref url="http://secunia.com/advisories/39295" source="SECUNIA" adv="1">39295</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11160" source="OVAL">oval:org.mitre.oval:def:11160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers prev="1" num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0009" published="2010-04-05" name="CVE-2010-0009" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://couchdb.apache.org/security.html" source="CONFIRM" patch="1" adv="1">http://couchdb.apache.org/security.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=578572" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=578572</ref>
      <ref url="http://www.securityfocus.com/bid/39116" source="BID">39116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510427/100/0/threaded" source="BUGTRAQ">20100331 [SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability</ref>
      <ref url="http://www.osvdb.org/63350" source="OSVDB">63350</ref>
      <ref url="http://secunia.com/advisories/39146" source="SECUNIA" adv="1">39146</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-03/0267.html" source="BUGTRAQ">20100331 [SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="couchdb">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0010" published="2010-02-02" name="CVE-2010-0010" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55941" source="XF">modproxy-approxysendfb-bo(55941)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0240" source="VUPEN" adv="1">ADV-2010-0240</ref>
      <ref url="http://www.securitytracker.com/id?1023533" source="SECTRACK">1023533</ref>
      <ref url="http://www.securityfocus.com/bid/37966" source="BID">37966</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509185/100/0/threaded" source="BUGTRAQ">20100127 Mod_proxy from apache 1.3 - Integer overflow which causes heap overflow.</ref>
      <ref url="http://site.pi3.com.pl/adv/mod_proxy.txt" source="MISC">http://site.pi3.com.pl/adv/mod_proxy.txt</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/38319" source="SECUNIA" adv="1">38319</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txt</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7923" source="OVAL">oval:org.mitre.oval:def:7923</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">SSRT090208</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497311408250&amp;w=2" source="HP">HPSBOV02683</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://httpd.apache.org/dev/dist/CHANGES_1.3.42" source="CONFIRM">http://httpd.apache.org/dev/dist/CHANGES_1.3.42</ref>
      <ref url="http://blog.pi3.com.pl/?p=69" source="MISC">http://blog.pi3.com.pl/?p=69</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.html" source="FULLDISC">20100127 Mod_proxy from apache 1.3 - Integer overflow which causes heap overflow.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="0.8.11" />
        <vers num="0.8.14" />
        <vers num="1.0" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.2" />
        <vers num="1.3.20" />
        <vers num="1.3.22" />
        <vers num="1.3.23" />
        <vers num="1.3.24" />
        <vers num="1.3.25" />
        <vers num="1.3.26" />
        <vers num="1.3.27" />
        <vers num="1.3.28" />
        <vers num="1.3.29" />
        <vers num="1.3.3" />
        <vers num="1.3.30" />
        <vers num="1.3.31" />
        <vers num="1.3.32" />
        <vers num="1.3.33" />
        <vers num="1.3.34" />
        <vers num="1.3.35" />
        <vers num="1.3.36" />
        <vers num="1.3.37" />
        <vers num="1.3.38" />
        <vers num="1.3.39" />
        <vers num="1.3.4" />
        <vers num="1.3.40" />
        <vers prev="1" num="1.3.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0011" published="2010-02-25" name="CVE-2010-0011" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://github.com/Dieterbe/uzbl/downloads" source="CONFIRM" patch="1">http://github.com/Dieterbe/uzbl/downloads</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56612" source="XF">uzbl-evaljs-command-execution(56612)</ref>
      <ref url="http://www.uzbl.org/news.php?id=22" source="CONFIRM">http://www.uzbl.org/news.php?id=22</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/06/3" source="MLIST">[oss-security] 20100106 Re: CVE request - uzbl remote code execution</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/06/1" source="MLIST">[oss-security] 20100106 CVE request - uzbl remote code execution</ref>
      <ref url="http://lists.uzbl.org/pipermail/uzbl-dev-uzbl.org/2010-January/000586.html" source="MLIST">[uzbl-dev] 20100102 Fw: Uzbl: security issue</ref>
      <ref url="http://github.com/Dieterbe/uzbl/commit/1958b52d41cba96956dc1995660de49525ed1047" source="CONFIRM">http://github.com/Dieterbe/uzbl/commit/1958b52d41cba96956dc1995660de49525ed1047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uzbl" name="uzbl">
        <vers prev="1" num="2009.12.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0012" published="2010-01-08" name="CVE-2010-0012" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/500625" source="CONFIRM">https://launchpad.net/bugs/500625</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55454" source="XF">transmission-name-directory-traversal(55454)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0071" source="VUPEN">ADV-2010-0071</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/06/4" source="MLIST">[oss-security] 20100106 Re: CVE Request: Transmission</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/06/2" source="MLIST">[oss-security] 20100106 CVE Request: Transmission</ref>
      <ref url="http://www.mail-archive.com/debian-devel-changes@lists.debian.org/msg264483.html" source="MLIST">[debian-devel-changes] 20100105 Accepted transmission 1.77-1 (source all amd64)</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1967" source="DEBIAN">DSA-1967</ref>
      <ref url="http://trac.transmissionbt.com/wiki/Changes#version-1.77" source="CONFIRM">http://trac.transmissionbt.com/wiki/Changes#version-1.77</ref>
      <ref url="http://trac.transmissionbt.com/changeset/9829/" source="CONFIRM">http://trac.transmissionbt.com/changeset/9829/</ref>
      <ref url="http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz</ref>
      <ref url="http://secunia.com/advisories/38005" source="SECUNIA">38005</ref>
      <ref url="http://secunia.com/advisories/37993" source="SECUNIA">37993</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transmissionbt" name="transmission">
        <vers num="1.22" />
        <vers num="1.34" />
        <vers num="1.75" />
        <vers num="1.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0013" published="2010-01-09" name="CVE-2010-0013" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122.  NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=552483" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=552483</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1020" source="VUPEN">ADV-2010-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3663" source="VUPEN" adv="1">ADV-2009-3663</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3662" source="VUPEN" adv="1">ADV-2009-3662</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/07/2" source="MLIST">[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/07/1" source="MLIST">[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/02/1" source="MLIST">[oss-security] 20100102 CVE request - pidgin MSN arbitrary file upload</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:085" source="MANDRIVA">MDVSA-2010:085</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022203.1-1" source="SUNALERT">1022203</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-277450-1" source="SUNALERT">277450</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/37961" source="SECUNIA">37961</ref>
      <ref url="http://secunia.com/advisories/37954" source="SECUNIA" adv="1">37954</ref>
      <ref url="http://secunia.com/advisories/37953" source="SECUNIA" adv="1">37953</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10333" source="OVAL">oval:org.mitre.oval:def:10333</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033848.html" source="FEDORA">FEDORA-2010-0429</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/033771.html" source="FEDORA">FEDORA-2010-0368</ref>
      <ref url="http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html" source="MISC">http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html</ref>
      <ref url="http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c" source="CONFIRM">http://developer.pidgin.im/viewmtn/revision/diff/3d02401cf232459fc80c0837d31e05fae7ae5467/with/c64a1adc8bda2b4aeaae1f273541afbc4f71b810/libpurple/protocols/msn/slp.c</ref>
      <ref url="http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810" source="CONFIRM">http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810</ref>
      <ref url="http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f" source="MISC">http://d.pidgin.im/viewmtn/revision/info/4be2df4f72bd8a55cdae7f2554b73342a497c92f</ref>
      <ref url="http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467" source="MISC">http://d.pidgin.im/viewmtn/revision/info/3d02401cf232459fc80c0837d31e05fae7ae5467</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0014" published="2010-01-14" name="CVE-2010-0014" modified="2010-01-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://fedorahosted.org/sssd/wiki/Releases/Notes-1.0.1" source="CONFIRM" patch="1">https://fedorahosted.org/sssd/wiki/Releases/Notes-1.0.1</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=553233" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=553233</ref>
      <ref url="http://www.securityfocus.com/bid/37747" source="BID">37747</ref>
      <ref url="http://secunia.com/advisories/38160" source="SECUNIA" adv="1">38160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="sssd">
        <vers num="0.2.1" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0015" published="2010-01-14" name="CVE-2010-0015" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/11/6" source="MLIST">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/08/2" source="MLIST">[oss-security] 20100109 Re: CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/08/1" source="MLIST">[oss-security] 20100108 Re: CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/07/3" source="MLIST">[oss-security] 20100107 CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:112" source="MANDRIVA">MDVSA-2010:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:111" source="MANDRIVA">MDVSA-2010:111</ref>
      <ref url="http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&amp;view=markup" source="CONFIRM">http://svn.debian.org/viewsvn/pkg-glibc/glibc-package/trunk/debian/patches/any/submitted-nis-shadow.diff?revision=4062&amp;view=markup</ref>
      <ref url="http://sourceware.org/bugzilla/show_bug.cgi?id=11134" source="MISC">http://sourceware.org/bugzilla/show_bug.cgi?id=11134</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126320570505651&amp;w=2" source="MLIST">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126320356003425&amp;w=2" source="MLIST">[oss-security] 20100111 Re: CVE id request: GNU libc: NIS shadow password leakage</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560333</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.10.2" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0016" published="2010-02-10" name="CVE-2010-0016" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx" source="MS">MS10-006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8278" source="OVAL">oval:org.mitre.oval:def:8278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="-" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:home" />
        <vers num="-" edition="sp3" />
        <vers num="-" edition="sp3:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0017" published="2010-02-10" name="CVE-2010-0017" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx" source="MS" patch="1" adv="1">MS10-006</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8298" source="OVAL">oval:org.mitre.oval:def:8298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="-" edition="r2" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0018" published="2010-01-13" name="CVE-2010-0018" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code via compressed data that represents a crafted EOT font, aka "Microtype Express Compressed Fonts Integer Flaw in the LZCOMP Decompressor Vulnerability."</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx


This security update is rated Critical for Microsoft Windows 2000, and is rated Low for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. For more information, see the subsection, Affected and Non-Affected Software, in this section.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012B.html" source="CERT">TA10-012B</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx" source="MS" patch="1" adv="1">MS10-001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0095" source="VUPEN" adv="1">ADV-2010-0095</ref>
      <ref url="http://www.securitytracker.com/id?1023432" source="SECTRACK">1023432</ref>
      <ref url="http://www.securityfocus.com/bid/37671" source="BID">37671</ref>
      <ref url="http://secunia.com/advisories/35457" source="SECUNIA" adv="1">35457</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8324" source="OVAL">oval:org.mitre.oval:def:8324</ref>
      <ref url="http://osvdb.org/61651" source="OSVDB">61651</ref>
      <ref url="http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx" source="MISC">http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0019" published="2010-08-11" name="CVE-2010-0019" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-060.mspx" source="MS" patch="1" adv="1">MS10-060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="silverlight">
        <vers num="3.0.40624.00" />
        <vers num="3.0.40723.0" />
        <vers prev="1" num="3.0.40818.0" />
        <vers prev="1" num="3.0.50106.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0020" published="2010-02-10" name="CVE-2010-0020" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" source="MS" patch="1" adv="1">MS10-012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8438" source="OVAL">oval:org.mitre.oval:def:8438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0021" published="2010-02-10" name="CVE-2010-0021" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" source="MS" patch="1" adv="1">MS10-012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8524" source="OVAL">oval:org.mitre.oval:def:8524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0022" published="2010-02-10" name="CVE-2010-0022" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" source="MS" patch="1" adv="1">MS10-012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8314" source="OVAL">oval:org.mitre.oval:def:8314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0023" published="2010-02-10" name="CVE-2010-0023" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx" source="MS" patch="1" adv="1">MS10-011</ref>
      <ref url="http://secunia.com/advisories/38509" source="SECUNIA">38509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8304" source="OVAL">oval:org.mitre.oval:def:8304</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0024" published="2010-04-14" name="CVE-2010-0024" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx" source="MS" patch="1" adv="1">MS10-024</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7067" source="OVAL">oval:org.mitre.oval:def:7067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2010" edition="-" />
        <vers num="2010" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0025" published="2010-04-14" name="CVE-2010-0025" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-024.mspx" source="MS" patch="1" adv="1">MS10-024</ref>
      <ref url="http://secunia.com/advisories/39253" source="SECUNIA">39253</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12175" source="OVAL">oval:org.mitre.oval:def:12175</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2010" edition="-" />
        <vers num="2010" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0026" published="2010-02-10" name="CVE-2010-0026" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-010.mspx" source="MS" adv="1">MS10-010</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8006" source="OVAL">oval:org.mitre.oval:def:8006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0027" published="2010-01-22" name="CVE-2010-0027" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx" source="MS" patch="1" adv="1">MS10-007</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" patch="1" adv="1">MS10-002</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55773" source="XF">ie-url-code-execution(55773)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-016/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-016/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509470/100/0/threaded" source="BUGTRAQ">20100209 ZDI-10-016: Microsoft Windows ShellExecute Improper Sanitization Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8464" source="OVAL">oval:org.mitre.oval:def:8464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.5730" edition="unknown" />
        <vers num="7.0.5730" edition="unknown:gold" />
        <vers num="7.0.5730.11" />
        <vers num="7.00.5730.1100" />
        <vers num="7.00.6000.16386" />
        <vers num="7.00.6000.16441" />
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0028" published="2010-02-10" name="CVE-2010-0028" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-005.mspx" source="MS" patch="1" adv="1">MS10-005</ref>
      <ref url="http://secunia.com/advisories/36634" source="SECUNIA">36634</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8429" source="OVAL">oval:org.mitre.oval:def:8429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0029" published="2010-02-10" name="CVE-2010-0029" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8410" source="OVAL">oval:org.mitre.oval:def:8410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0030" published="2010-02-10" name="CVE-2010-0030" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8050" source="OVAL">oval:org.mitre.oval:def:8050</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0031" published="2010-02-10" name="CVE-2010-0031" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8081" source="OVAL">oval:org.mitre.oval:def:8081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0032" published="2010-02-10" name="CVE-2010-0032" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8303" source="OVAL">oval:org.mitre.oval:def:8303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0033" published="2010-02-10" name="CVE-2010-0033" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7711" source="OVAL">oval:org.mitre.oval:def:7711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0034" published="2010-02-10" name="CVE-2010-0034" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx" source="MS" patch="1" adv="1">MS10-004</ref>
      <ref url="http://www.securitytracker.com/id?1023563" source="SECTRACK">1023563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8268" source="OVAL">oval:org.mitre.oval:def:8268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0035" published="2010-02-10" name="CVE-2010-0035" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx


"This vulnerability only affects domain controllers. Servers that do not perform the role of domain controllers are not affected."</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx" source="MS" patch="1" adv="1">MS10-014</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8428" source="OVAL">oval:org.mitre.oval:def:8428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0036" published="2010-01-20" name="CVE-2010-0036" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37868" source="BID" patch="1">37868</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55746" source="XF">macos-coreaudio-mp4-bo(55746)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0173" source="VUPEN">ADV-2010-0173</ref>
      <ref url="http://www.securitytracker.com/id?1023472" source="SECTRACK">1023472</ref>
      <ref url="http://support.apple.com/kb/HT4013" source="CONFIRM">http://support.apple.com/kb/HT4013</ref>
      <ref url="http://support.apple.com/kb/HT4004" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4004</ref>
      <ref url="http://secunia.com/advisories/38241" source="SECUNIA">38241</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html" source="APPLE">APPLE-SA-2010-01-19-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html" source="APPLE">APPLE-SA-2010-02-02-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0037" published="2010-01-20" name="CVE-2010-0037" modified="2010-01-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55747" source="XF">macos-imageraw-dng-bo(55747)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0173" source="VUPEN">ADV-2010-0173</ref>
      <ref url="http://www.securitytracker.com/id?1023473" source="SECTRACK">1023473</ref>
      <ref url="http://www.securityfocus.com/bid/37869" source="BID">37869</ref>
      <ref url="http://support.apple.com/kb/HT4004" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4004</ref>
      <ref url="http://secunia.com/advisories/38241" source="SECUNIA">38241</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html" source="APPLE">APPLE-SA-2010-01-19-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0038" published="2010-02-03" name="CVE-2010-0038" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38040" source="BID">38040</ref>
      <ref url="http://support.apple.com/kb/HT4013" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4013</ref>
      <ref url="http://osvdb.org/62128" source="OSVDB">62128</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-02-02-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0" />
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.1.1" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0039" published="2010-12-21" name="CVE-2010-0039" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write access to an intranet FTP server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4298" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4298</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-12-16-1</ref>
      <ref url="http://www.securitytracker.com/id?1024907" source="SECTRACK">1024907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_express">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="airport_express_base_station_firmware">
        <vers num="3.84" />
        <vers num="4.0.9" />
        <vers num="6.1" />
        <vers num="6.3" />
        <vers num="7.3.2" />
        <vers num="7.4.1" />
        <vers prev="1" num="7.4.2" />
      </prod>
      <prod vendor="apple" name="airport_extreme">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="airport_extreme_base_station_firmware">
        <vers num="5.5" />
        <vers num="5.7" />
      </prod>
      <prod vendor="apple" name="time_capsule">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0040" published="2010-03-15" name="CVE-2010-0040" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html



ColorSync
CVE-ID:  CVE-2010-0040
Available for:  Windows 7, Vista, XP
Impact:  Viewing a maliciously crafted image with an embedded color
profile may lead to an unexpected application termination or
arbitrary code execution
Description:  An integer overflow, that could result in a heap buffer
overflow, exists in the handling of images with an embedded color
profile. Opening a maliciously crafted image with an embedded color
profile may lead to an unexpected application termination or
arbitrary code execution. The issue is addressed by performing
additional validation of color profiles. This issue does not affect
Mac OS X systems. Credit to Sebastien Renaud of VUPEN Vulnerability
Research Team for reporting this issue.
</descript>
    </desc>
    <sols>
      <sol source="nvd">Per:   http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html



'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38674" source="BID" patch="1">38674</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56826" source="XF">safari-colorsync-bo(56826)</ref>
      <ref url="http://www.securitytracker.com/id?1023706" source="SECTRACK">1023706</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6741" source="OVAL">oval:org.mitre.oval:def:6741</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE">APPLE-SA-2010-03-30-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0041" published="2010-03-15" name="CVE-2010-0041" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.</descript>
      <descript source="nvd">Per:   http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html


ImageIO
CVE-ID:  CVE-2010-0041
Available for:  Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may result in sending
data from Safari's memory to the website
Description:  An uninitialized memory access issue exists in
ImageIO's handling of BMP images. Visiting a maliciously crafted
website may result in sending data from Safari's memory to the
website. This issue is addressed through improved memory handling and
additional validation of BMP images. Credit to Matthew 'j00ru'
Jurczyk of Hispasec for reporting this issue.

</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38676" source="BID" patch="1">38676</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.securitytracker.com/id?1023706" source="SECTRACK">1023706</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6885" source="OVAL">oval:org.mitre.oval:def:6885</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE">APPLE-SA-2010-03-30-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0042" published="2010-03-15" name="CVE-2010-0042" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html


'ImageIO
CVE-ID:  CVE-2010-0042
Available for:  Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may result in sending
data from Safari's memory to the website
Description:  An uninitialized memory access issue exists in
ImageIO's handling of TIFF images. Visiting a maliciously crafted
website may result in sending data from Safari's memory to the
website. This issue is addressed through improved memory handling and
additional validation of TIFF images. Credit to Matthew 'j00ru'
Jurczyk of Hispasec for reporting this issue.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38677" source="BID" patch="1">38677</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.securitytracker.com/id?1023706" source="SECTRACK">1023706</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7561" source="OVAL">oval:org.mitre.oval:def:7561</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE">APPLE-SA-2010-03-30-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0043" published="2010-03-15" name="CVE-2010-0043" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html


'ImageIO
CVE-ID:  CVE-2010-0043
Available for:  Windows 7, Vista, XP
Impact:  Processing a maliciously crafted TIFF image may lead to an
unexpected application termination or arbitrary code execution
Description:  A memory corruption issue exists in the handling of
TIFF images. Processing a maliciously crafted TIFF image may lead to
an unexpected application termination or arbitrary code execution.
This issue is addressed through improved memory handling. Credit to
Gus Mueller of Flying Meat for reporting this issue.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38673" source="BID" patch="1">38673</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.securitytracker.com/id?1023706" source="SECTRACK">1023706</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6901" source="OVAL">oval:org.mitre.oval:def:6901</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE">APPLE-SA-2010-03-30-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0044" published="2010-03-15" name="CVE-2010-0044" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'PubSub
CVE-ID:  CVE-2010-0044
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting or updating a feed may result in a cookie being
set, even if Safari is configured to block cookies
Description:  An implementation issue exists in the handling of
cookies set by RSS and Atom feeds. Visiting or updating a feed may
result in a cookie being set, even if Safari is configured to block
cookies via the "Accept Cookies" preference. This update addresses
the issue by respecting the preference while updating or viewing
feeds.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38675" source="BID" patch="1">38675</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56830" source="XF">safari-pubsub-security-bypass(56830)</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7051" source="OVAL">oval:org.mitre.oval:def:7051</ref>
      <ref url="http://osvdb.org/62937" source="OSVDB">62937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0045" published="2010-03-15" name="CVE-2010-0045" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

CVE-ID:  CVE-2010-0045
Available for:  Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to arbitrary
code execution
Description:  An issue in Safari's handling of external URL schemes
may cause a local file to be opened in response to a URL encountered
on a web page. Visiting a maliciously crafted website may lead to
arbitrary code execution. This update addresses the issue through
improved validation of external URLs. This issue does not affect Mac
OS X systems. Credit to Billy Rios and Microsoft Vulnerability
Research (MSVR) for reporting this issue.
</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.securitytracker.com/id?1023706" source="SECTRACK">1023706</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6817" source="OVAL">oval:org.mitre.oval:def:6817</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0046" published="2010-03-15" name="CVE-2010-0046" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'WebKit
CVE-ID:  CVE-2010-0046
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A memory corruption issue exists in WebKit's handling
of CSS format() arguments. Visiting a maliciously crafted website may
lead to an unexpected application termination or arbitrary code
execution. This issue is addressed through improved handling of CSS
format() arguments. Credit to Robert Swiecki of Google Inc. for
reporting this issue.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7053" source="OVAL">oval:org.mitre.oval:def:7053</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0047" published="2010-03-15" name="CVE-2010-0047" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'WebKit
CVE-ID:  CVE-2010-0047
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in the handling of HTML
object element fallback content. Visiting a maliciously crafted
website may lead to an unexpected application termination or
arbitrary code execution. This issue is addressed through improved
memory reference tracking. Credit to wushi of team509, working with
TippingPoint's Zero Day Initiative for reporting this issue.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6882" source="OVAL">oval:org.mitre.oval:def:6882</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0048" published="2010-03-15" name="CVE-2010-0048" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

CVE-ID:  CVE-2010-0048
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in WebKit's parsing of
XML documents. Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution. This
issue is addressed through improved memory reference tracking.
</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID">38671</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7135" source="OVAL">oval:org.mitre.oval:def:7135</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0049" published="2010-03-15" name="CVE-2010-0049" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.

CVE-ID:  CVE-2010-0049
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in the handling of HTML
elements containing right-to-left displayed text. Visiting a
maliciously crafted website may lead to an unexpected application
termination or arbitrary code execution. This issue is addressed
through improved memory reference tracking. Credit to wushi&amp;Z of
team509 for reporting this issue.
</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6810" source="OVAL">oval:org.mitre.oval:def:6810</ref>
      <ref url="http://osvdb.org/62942" source="OSVDB">62942</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=863" source="IDEFENSE">20100311 Multiple Vendor WebKit HTML Element Use After Free Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0050" published="2010-03-15" name="CVE-2010-0050" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html


'WebKit
CVE-ID:  CVE-2010-0050
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in WebKit's handling of
incorrectly nested HTML tags. Visiting a maliciously crafted website
may lead to an unexpected application termination or arbitrary code
execution. This issue is addressed through improved memory reference
tracking. Credit to wushi&amp;Z of team509 working with TippingPoint's
Zero Day Initiative for reporting this issue.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56836" source="XF">safari-nested-html-code-exec(56836)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7587" source="OVAL">oval:org.mitre.oval:def:7587</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0051" published="2010-03-15" name="CVE-2010-0051" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document.  NOTE: this might overlap CVE-2010-0651.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'WebKit
CVE-ID:  CVE-2010-0051
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to the
disclosure of sensitive information
Description:  An implementation issue exists in WebKit's handling of
cross-origin stylesheet requests. Visiting a maliciously crafted
website may disclose the content of protected resources on another
website. This update addresses the issue by performing additional
validation on stylesheets that are loaded during a cross-origin
request.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56837" source="XF">safari-stylesheet-info-disclosure(56837)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://websec.sv.cmu.edu/css/css.pdf" source="MISC">http://websec.sv.cmu.edu/css/css.pdf</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7554" source="OVAL">oval:org.mitre.oval:def:7554</ref>
      <ref url="http://osvdb.org/62944" source="OSVDB">62944</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9877" source="MISC">http://code.google.com/p/chromium/issues/detail?id=9877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0052" published="2010-03-15" name="CVE-2010-0052" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

CVE-ID:  CVE-2010-0052
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in WebKit's handling of
callbacks for HTML elements. Visiting a maliciously crafted website
may lead to an unexpected application termination or arbitrary code
execution. This issue is addressed through improved memory reference
tracking. Credit: Apple.

</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7403" source="OVAL">oval:org.mitre.oval:def:7403</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0053" published="2010-03-15" name="CVE-2010-0053" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

CVE-ID:  CVE-2010-0053
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in the rendering of
content with a CSS display property set to 'run-in'. Visiting a
maliciously crafted website may lead to an unexpected application
termination or arbitrary code execution. This issue is addressed
through improved memory reference tracking. Credit to wushi of
team509, working with TippingPoint's Zero Day Initiative for
reporting this issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID">38671</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7323" source="OVAL">oval:org.mitre.oval:def:7323</ref>
      <ref url="http://osvdb.org/62948" source="OSVDB">62948</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0054" published="2010-03-15" name="CVE-2010-0054" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.</descript>
      <descript source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'WebKit
CVE-ID:  CVE-2010-0054
Available for:  Mac OS X v10.4.11, Mac OS X Server v10.4.11,
Mac OS X v10.5.8, Mac OS X Server v10.5.8,
Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later,
Windows 7, Vista, XP
Impact:  Visiting a maliciously crafted website may lead to an
unexpected application termination or arbitrary code execution
Description:  A use-after-free issue exists in WebKit's handling of
HTML image elements. Visiting a maliciously crafted website may lead
to an unexpected application termination or arbitrary code execution.
This issue is addressed through improved memory reference tracking.
Credit: Apple.'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html

'Safari 4.0.5 is available via the Apple Software Update application,
or Apple's Safari download site at:
http://www.apple.com/safari/download/'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38671" source="BID" patch="1">38671</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securitytracker.com/id?1023708" source="SECTRACK">1023708</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4070" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4070</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6915" source="OVAL">oval:org.mitre.oval:def:6915</ref>
      <ref url="http://osvdb.org/62949" source="OSVDB">62949</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-03-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0055" published="2010-03-30" name="CVE-2010-0055" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0056" published="2010-03-30" name="CVE-2010-0056" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Cocoa spell checking in AppKit in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0057" published="2010-03-30" name="CVE-2010-0057" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0058" published="2010-03-30" name="CVE-2010-0058" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">freshclam in ClamAV in Apple Mac OS X 10.5.8 with Security Update 2009-005 has an incorrect launchd.plist ProgramArguments key and consequently does not run, which might allow remote attackers to introduce viruses into the system.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0059" published="2010-03-30" name="CVE-2010-0059" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-041" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-041</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510517/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-041: Apple QuickTime QDM2/QDCA Atom Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6922" source="OVAL">oval:org.mitre.oval:def:6922</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0060" published="2010-03-30" name="CVE-2010-0060" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7513" source="OVAL">oval:org.mitre.oval:def:7513</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0062" published="2010-03-30" name="CVE-2010-0062" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-036" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-036</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510510/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-036: Apple QuickTime H.263 PictureHeader Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6626" source="OVAL">oval:org.mitre.oval:def:6626</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0063" published="2010-03-30" name="CVE-2010-0063" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/slices/2000.html

'Incomplete Blacklist - CWE-184'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0064" published="2010-03-30" name="CVE-2010-0064" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0065" published="2010-03-30" name="CVE-2010-0065" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0066" published="2010-01-12" name="CVE-2010-0066" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Access Manager Identity Server component in Oracle Application Server 7.0.4.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023438" source="SECTRACK">1023438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.4.2" />
        <vers num="7.0.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0067" published="2010-01-12" name="CVE-2010-0067" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023438" source="SECTRACK">1023438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.3" />
        <vers num="10.1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0068" published="2010-01-12" name="CVE-2010-0068" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP2, and 10.0 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0069" published="2010-01-12" name="CVE-2010-0069" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0, SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP1, and 10.3.0 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT" patch="1">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3.0" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0070" published="2010-01-12" name="CVE-2010-0070" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023438" source="SECTRACK">1023438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.3" />
        <vers num="10.1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0071" published="2010-01-12" name="CVE-2010-0071" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0072" published="2010-01-12" name="CVE-2010-0072" modified="2010-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a buffer overflow in observiced.exe that allows remote attackers to execute arbitrary code via vectors related to a "reverse lookup of connections" to TCP port 10000.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0073" published="2010-04-14" name="CVE-2010-0073" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0216" source="VUPEN" patch="1" adv="1">ADV-2010-0216</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0073.html</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="weblogic_server">
        <vers num="10.3" />
      </prod>
      <prod vendor="oracle" name="weblogic_server_component">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="6.1" edition="sp7" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0074" published="2010-01-12" name="CVE-2010-0074" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0SP7, 8.1SP6, 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp2" />
        <vers num="10.3.1" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0075" published="2010-01-12" name="CVE-2010-0075" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HRMS (Self Service) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0076" published="2010-01-12" name="CVE-2010-0076" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database">
        <vers num="3.2.1.00.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0077" published="2010-01-12" name="CVE-2010-0077" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the CRM Technical Foundation (mobile) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0078" published="2010-01-12" name="CVE-2010-0078" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2MP3, 10.0MP2, and 10.3.1 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp2" />
        <vers num="10.3.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0079" published="2010-01-12" name="CVE-2010-0079" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, and CVE-2009-3877.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="r27.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0080" published="2010-01-12" name="CVE-2010-0080" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:N)" CVSS_score="4.9" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="6.8" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HCM - eProfile component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 Bundle, #21 and 9.0 Bundle #11 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-012A.html" source="CERT">TA10-012A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.9" edition="bundle21" />
        <vers num="9.0" edition="bundle11" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0081" published="2010-07-13" name="CVE-2010-0081" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Server Control component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0082" published="2010-04-01" name="CVE-2010-0082" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13934" source="OVAL">oval:org.mitre.oval:def:13934</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11576" source="OVAL">oval:org.mitre.oval:def:11576</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0083" published="2010-07-13" name="CVE-2010-0083" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle OpenSolaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensolaris">
        <vers num="10" />
        <vers num="8" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0084" published="2010-04-01" name="CVE-2010-0084" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14061" source="OVAL">oval:org.mitre.oval:def:14061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11120" source="OVAL">oval:org.mitre.oval:def:11120</ref>
      <ref url="http://osvdb.org/63482" source="OSVDB">63482</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0085" published="2010-04-01" name="CVE-2010-0085" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13803" source="OVAL">oval:org.mitre.oval:def:13803</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10474" source="OVAL">oval:org.mitre.oval:def:10474</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0086" published="2010-04-13" name="CVE-2010-0086" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023869" source="SECTRACK">1023869</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0087" published="2010-04-01" name="CVE-2010-0087" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13959" source="OVAL">oval:org.mitre.oval:def:13959</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0088" published="2010-04-01" name="CVE-2010-0088" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14321" source="OVAL">oval:org.mitre.oval:def:14321</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11173" source="OVAL">oval:org.mitre.oval:def:11173</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0089" published="2010-04-01" name="CVE-2010-0089" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'
</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14208" source="OVAL">oval:org.mitre.oval:def:14208</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0090" published="2010-04-01" name="CVE-2010-0090" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14237" source="OVAL">oval:org.mitre.oval:def:14237</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0091" published="2010-04-01" name="CVE-2010-0091" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9855" source="OVAL">oval:org.mitre.oval:def:9855</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13492" source="OVAL">oval:org.mitre.oval:def:13492</ref>
      <ref url="http://osvdb.org/63481" source="OSVDB">63481</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0092" published="2010-04-01" name="CVE-2010-0092" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN" adv="1">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA" adv="1">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14210" source="OVAL">oval:org.mitre.oval:def:14210</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10057" source="OVAL">oval:org.mitre.oval:def:10057</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0093" published="2010-04-01" name="CVE-2010-0093" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9877" source="OVAL">oval:org.mitre.oval:def:9877</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14288" source="OVAL">oval:org.mitre.oval:def:14288</ref>
      <ref url="http://osvdb.org/63485" source="OSVDB">63485</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0094" published="2010-04-01" name="CVE-2010-0094" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-051" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-051</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN" adv="1">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510527/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA" adv="1">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14351" source="OVAL">oval:org.mitre.oval:def:14351</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10851" source="OVAL">oval:org.mitre.oval:def:10851</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0095" published="2010-04-01" name="CVE-2010-0095" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14105" source="OVAL">oval:org.mitre.oval:def:14105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11621" source="OVAL">oval:org.mitre.oval:def:11621</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0097" published="2010-01-22" name="CVE-2010-0097" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/360341" source="CERT-VN">VU#360341</ref>
      <ref url="https://www.isc.org/advisories/CVE-2010-0097" source="CONFIRM">https://www.isc.org/advisories/CVE-2010-0097</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT">RHSA-2010:0095</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0062.html" source="REDHAT">RHSA-2010:0062</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=554851" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=554851</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55753" source="XF">bind-dnssecnsec-cache-poisoning(55753)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1352" source="VUPEN">ADV-2010-1352</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0981" source="VUPEN">ADV-2010-0981</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0622" source="VUPEN">ADV-2010-0622</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0176" source="VUPEN" adv="1">ADV-2010-0176</ref>
      <ref url="http://www.ubuntu.com/usn/USN-888-1" source="UBUNTU">USN-888-1</ref>
      <ref url="http://www.securityfocus.com/bid/37865" source="BID">37865</ref>
      <ref url="http://www.osvdb.org/61853" source="OSVDB">61853</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:021" source="MANDRIVA">MDVSA-2010:021</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2054" source="DEBIAN">DSA-2054</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021798.1-1" source="SUNALERT">1021798</ref>
      <ref url="http://securitytracker.com/id?1023474" source="SECTRACK">1023474</ref>
      <ref url="http://secunia.com/advisories/40086" source="SECUNIA">40086</ref>
      <ref url="http://secunia.com/advisories/39582" source="SECUNIA">39582</ref>
      <ref url="http://secunia.com/advisories/39334" source="SECUNIA">39334</ref>
      <ref url="http://secunia.com/advisories/38240" source="SECUNIA" adv="1">38240</ref>
      <ref url="http://secunia.com/advisories/38219" source="SECUNIA" adv="1">38219</ref>
      <ref url="http://secunia.com/advisories/38169" source="SECUNIA" adv="1">38169</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9357" source="OVAL">oval:org.mitre.oval:def:9357</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7430" source="OVAL">oval:org.mitre.oval:def:7430</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7212" source="OVAL">oval:org.mitre.oval:def:7212</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12205" source="OVAL">oval:org.mitre.oval:def:12205</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127195582210247&amp;w=2" source="HP">SSRT100004</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127195582210247&amp;w=2" source="HP">SSRT100004</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034202.html" source="FEDORA">FEDORA-2010-0868</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034196.html" source="FEDORA">FEDORA-2010-0861</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
      <ref url="ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt" source="CONFIRM">ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.2.0" />
        <vers num="9.2.1" />
        <vers num="9.2.2" edition="p3" />
        <vers num="9.2.3" />
        <vers num="9.2.4" />
        <vers num="9.2.5" />
        <vers num="9.2.6" />
        <vers num="9.2.7" />
        <vers num="9.2.9" />
        <vers num="9.3" />
        <vers num="9.3.0" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
        <vers num="9.3.3" />
        <vers num="9.4" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.2" />
        <vers num="9.4.3" />
        <vers num="9.4.3p1" />
        <vers num="9.4.3p2" />
        <vers num="9.4.3p3" />
        <vers num="9.4.3p4" />
        <vers num="9.5" />
        <vers num="9.5.0" edition="rc1" />
        <vers num="9.5.0-p1" />
        <vers num="9.5.0-p2" />
        <vers num="9.5.0a1" />
        <vers num="9.5.0a2" />
        <vers num="9.5.0a3" />
        <vers num="9.5.0a4" />
        <vers num="9.5.0a5" />
        <vers num="9.5.0a6" />
        <vers num="9.5.0b1" />
        <vers num="9.5.0b2" />
        <vers num="9.5.0b3" />
        <vers num="9.5.1" edition="rc1" />
        <vers num="9.5.1b1" />
        <vers num="9.5.1b2" />
        <vers num="9.5.1b3" />
        <vers num="9.5.2" />
        <vers num="9.5.2p1" />
        <vers num="9.6.0" edition="p1" />
        <vers num="9.6.0" edition="rc2" />
        <vers num="9.6.0a1" />
        <vers num="9.6.1" edition="p1" />
        <vers num="9.6.1" edition="p2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0098" published="2010-04-08" name="CVE-2010-0098" modified="2010-08-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39262" source="BID" patch="1">39262</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1826" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1826</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1206" source="VUPEN">ADV-2010-1206</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0909" source="VUPEN">ADV-2010-0909</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0832" source="VUPEN">ADV-2010-0832</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0827" source="VUPEN">ADV-2010-0827</ref>
      <ref url="http://www.ubuntu.com/usn/USN-926-1" source="UBUNTU">USN-926-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/08/3" source="MLIST">[oss-security] 20100407 Re: ClamAV small issues</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/06/4" source="MLIST">[oss-security] 20100406 ClamAV small issues</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:082" source="MANDRIVA">MDVSA-2010:082</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39329" source="SECUNIA" adv="1">39329</ref>
      <ref url="http://secunia.com/advisories/39293" source="SECUNIA">39293</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96" source="CONFIRM">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc" />
        <vers num="0.80" edition="rc2" />
        <vers num="0.80" edition="rc3" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" edition="rc1" />
        <vers num="0.84" edition="rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" edition="rc1" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.9" edition="rc1" />
        <vers num="0.90" edition="rc1" />
        <vers num="0.90" edition="rc1.1" />
        <vers num="0.90" edition="rc2" />
        <vers num="0.90" edition="rc3" />
        <vers num="0.90.1" />
        <vers num="0.90.2" />
        <vers num="0.90.3" />
        <vers num="0.91" edition="rc1" />
        <vers num="0.91" edition="rc2" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
        <vers num="0.95" edition="rc1" />
        <vers num="0.95" edition="rc2" />
        <vers num="0.95.1" />
        <vers num="0.95.2" />
        <vers num="0.95.3" />
        <vers prev="1" num="0.96" edition="rc1" />
        <vers prev="1" num="0.96" edition="rc2" />
      </prod>
      <prod vendor="clamavs" name="clamav">
        <vers num="0.04" />
        <vers num="0.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-0099" reject="1" published="2010-07-22" name="CVE-2010-0099" modified="2010-07-22">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0092.  Reason: This candidate is a duplicate of CVE-2010-0092.  Notes: All CVE users should reference CVE-2010-0092 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-0101" published="2010-05-04" name="CVE-2010-0101" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.lexmark.com/index?page=content&amp;id=TE87&amp;locale=EN&amp;userlocale=EN_US" source="CONFIRM" adv="1">http://support.lexmark.com/index?page=content&amp;id=TE87&amp;locale=EN&amp;userlocale=EN_US</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="25xxn">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c510">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c52x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c53x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c540">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c543">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c544">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c546">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c73x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c77x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c78x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c920">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="c935dn">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e120">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e238">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e23x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e240">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e240n">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e250">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e260">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e33x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e34x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e350">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e360d">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e360dn">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e450">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e460">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="e462">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="n4000">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="n4050e">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="n70xxe">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="n8120">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="n8130">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t430">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t64x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t650">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t652">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t654">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="t656">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="w840">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="w850">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x20x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x26x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x34x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x36x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x422">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x46x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x543">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x544">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x546">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x642">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x644">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x646">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x64xef">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x65x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x73x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x772e">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x782e">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x85x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x86x">
        <vers num="" />
      </prod>
      <prod vendor="lexmark" name="x94x">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0103" published="2010-03-10" name="CVE-2010-0103" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.</descript>
      <descript source="nvd">Per: http://www.energizer.com/usbcharger/download/March_8_2010_USB_Release__3_.pdf


"Energizer has discontinued sale of this product and has removed the site to download the software. In addition, the company is directing consumers that downloaded the Windows version of the software to uninstall or otherwise remove the software from your computer."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/154421" source="CERT-VN">VU#154421</ref>
      <ref url="http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software" source="MISC">http://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software</ref>
      <ref url="http://www.securityfocus.com/bid/38571" source="BID">38571</ref>
      <ref url="http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05" source="MISC">http://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="energizer" name="duo_usb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0104" published="2010-03-18" name="CVE-2010-0104" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Broadcom Integrated NIC Management Firmware 1.x before 1.40.0.0 and 8.x before 8.08 on the HP Small Form Factor and Microtower platforms allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/512705" source="CERT-VN">VU#512705</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471" source="HP" patch="1" adv="1">HPSBGN02511</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0631" source="VUPEN" adv="1">ADV-2010-0631</ref>
      <ref url="http://www.securityfocus.com/bid/38759" source="BID">38759</ref>
      <ref url="http://securitytracker.com/id?1023710" source="SECTRACK">1023710</ref>
      <ref url="http://secunia.com/advisories/39003" source="SECUNIA" adv="1">39003</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471" source="HP">HPSBGN02511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="broadcom" name="broadcom">
        <vers prev="1" num="integrated_nic_management_firmware" edition="1.24.0.9" />
        <vers prev="1" num="integrated_nic_management_firmware" edition="8.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0105" published="2010-04-27" name="CVE-2010-0105" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/39658" source="BID">39658</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securityreason.com/achievement_securityalert/83" source="SREASONRES">20100423 MacOS X 10.6.3 filesystem hfs Denial of Service Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0106" published="2010-02-19" name="CVE-2010-0106" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56354" source="XF">symantec-ondemand-dos(56354)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0410" source="VUPEN" adv="1">ADV-2010-0410</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_00" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_00</ref>
      <ref url="http://www.securitytracker.com/id?1023621" source="SECTRACK">1023621</ref>
      <ref url="http://www.securityfocus.com/bid/38219" source="BID">38219</ref>
      <ref url="http://secunia.com/advisories/38653" source="SECUNIA" adv="1">38653</ref>
      <ref url="http://osvdb.org/62414" source="OSVDB">62414</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.1.1" />
        <vers num="10.0.2" />
        <vers num="10.0.2.1" />
        <vers num="10.0.2.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.0.5" />
        <vers num="10.0.6" />
        <vers num="10.0.7" />
        <vers num="10.0.8" />
        <vers num="10.0.9" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate" />
        <vers num="10.1" edition="mp1" />
        <vers num="10.1" edition="mp1:corporate" />
        <vers num="10.1" edition="mr4" />
        <vers num="10.1" edition="mr4:corporate" />
        <vers num="10.1" edition="mr5" />
        <vers num="10.1" edition="mr5:corporate" />
        <vers num="10.1" edition="mr7" />
        <vers num="10.1" edition="mr7:corporate" />
        <vers num="10.1.0.1" edition="" />
        <vers num="10.1.0.1" edition=":corporate" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate" />
        <vers num="10.1.4.1" edition="" />
        <vers num="10.1.4.1" edition=":corporate" />
        <vers num="10.1.5" edition="" />
        <vers num="10.1.5" edition=":corporate" />
        <vers num="10.1.5.1" edition="" />
        <vers num="10.1.5.1" edition=":corporate" />
        <vers num="10.1.6" edition="" />
        <vers num="10.1.6" edition=":corporate" />
        <vers num="10.1.6.1" edition="" />
        <vers num="10.1.6.1" edition=":corporate" />
        <vers num="10.1.7" edition="" />
        <vers num="10.1.7" edition=":corporate" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":corporate" />
        <vers num="10.2" edition="mr2" />
        <vers num="10.2" edition="mr2:corporate" />
        <vers num="10.2" edition="mr3" />
        <vers num="10.2" edition="mr3:corporate" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="3.0" edition="mr1" />
        <vers num="3.0" edition="mr2" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" edition="mr4" />
        <vers num="3.1" edition="mr5" />
        <vers num="3.1" edition="mr7" />
        <vers num="3.1.0.396" />
        <vers num="3.1.0.401" />
        <vers num="3.1.394" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0107" published="2010-02-23" name="CVE-2010-0107" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.  NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56357" source="XF">symantec-symltcom-activex-bo(56357)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0411" source="VUPEN" adv="1">ADV-2010-0411</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_01" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_01</ref>
      <ref url="http://www.securitytracker.com/id?1023631" source="SECTRACK">1023631</ref>
      <ref url="http://www.securitytracker.com/id?1023630" source="SECTRACK">1023630</ref>
      <ref url="http://www.securitytracker.com/id?1023629" source="SECTRACK">1023629</ref>
      <ref url="http://www.securitytracker.com/id?1023628" source="SECTRACK">1023628</ref>
      <ref url="http://www.securityfocus.com/bid/38217" source="BID">38217</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509717/100/0/threaded" source="BUGTRAQ">20100224 VUPEN Security Research - Symantec Products "SYMLTCOM.dll" Buffer Overflow Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38654" source="SECUNIA" adv="1">38654</ref>
      <ref url="http://osvdb.org/62412" source="OSVDB">62412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="client_security">
        <vers num="3.0" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" edition="mr4" />
        <vers num="3.1" edition="mr5" />
        <vers num="3.1" edition="mr6" />
        <vers num="3.1.0.396" />
        <vers num="3.1.0.401" />
        <vers num="3.1.396" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="norton_360">
        <vers num="1.0" />
        <vers num="2.0" />
      </prod>
      <prod vendor="symantec" name="norton_antivirus">
        <vers num="2006" />
        <vers num="2007" />
        <vers num="2008" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2006" />
        <vers num="2007" />
        <vers num="2008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0108" published="2010-02-19" name="CVE-2010-0108" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56355" source="XF">scp-cliproxy-activex-bo(56355)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0412" source="VUPEN" adv="1">ADV-2010-0412</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_02" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100217_02</ref>
      <ref url="http://www.securityfocus.com/bid/38222" source="BID">38222</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509681/100/0/threaded" source="BUGTRAQ">20100219 [DSECRG-09-039] Symantec Antivirus 10.0 ActiveX - buffer Overflow.</ref>
      <ref url="http://secunia.com/advisories/38651" source="SECUNIA" adv="1">38651</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=139" source="MISC">http://dsecrg.com/pages/vul/show.php?id=139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.1.1" />
        <vers num="10.0.2" />
        <vers num="10.0.2.1" />
        <vers num="10.0.2.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.0.5" />
        <vers num="10.0.6" />
        <vers num="10.0.7" />
        <vers num="10.0.8" />
        <vers num="10.0.9" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate" />
        <vers num="10.1" edition="mp1" />
        <vers num="10.1" edition="mp1:corporate" />
        <vers num="10.1" edition="mr4" />
        <vers num="10.1" edition="mr4:corporate" />
        <vers num="10.1" edition="mr5" />
        <vers num="10.1" edition="mr5:corporate" />
        <vers num="10.1" edition="mr7" />
        <vers num="10.1" edition="mr7:corporate" />
        <vers num="10.1.0.1" edition="" />
        <vers num="10.1.0.1" edition=":corporate" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate" />
        <vers num="10.1.4.1" edition="" />
        <vers num="10.1.4.1" edition=":corporate" />
        <vers num="10.1.5" edition="" />
        <vers num="10.1.5" edition=":corporate" />
        <vers num="10.1.5.1" edition="" />
        <vers num="10.1.5.1" edition=":corporate" />
        <vers num="10.1.6" edition="" />
        <vers num="10.1.6" edition=":corporate" />
        <vers num="10.1.6.1" edition="" />
        <vers num="10.1.6.1" edition=":corporate" />
        <vers num="10.1.7" edition="" />
        <vers num="10.1.7" edition=":corporate" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":corporate" />
        <vers num="10.2" edition="mr2" />
        <vers num="10.2" edition="mr2:corporate" />
        <vers num="10.2" edition="mr3" />
        <vers num="10.2" edition="mr3:corporate" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="3.0" edition="mr1" />
        <vers num="3.0" edition="mr2" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers num="3.1" edition="mr4" />
        <vers num="3.1" edition="mr5" />
        <vers num="3.1" edition="mr7" />
        <vers num="3.1.0.396" />
        <vers num="3.1.0.401" />
        <vers num="3.1.394" />
        <vers num="3.1.400" />
        <vers num="3.1.401" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0110" published="2011-01-31" name="CVE-2010-0110" modified="2011-03-02" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="7.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.5" CVSS_base_score="7.9">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allow remote attackers to execute arbitrary code via (1) a long string to msgsys.exe, related to the AMSSendAlertAct function in AMSLIB.dll in the Intel Alert Handler service (aka Symantec Intel Handler service); a long (2) modem string or (3) PIN number to msgsys.exe, related to pagehndl.dll in the Intel Alert Handler service; or (4) a message to msgsys.exe, related to iao.exe in the Intel Alert Originator service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64940" source="XF">symantec-intel-ams2-bo(64940)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-032" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-032</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-031" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-031</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-030" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-030</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-028" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-028</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0234" source="VUPEN" adv="1">ADV-2011-0234</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_00" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_00</ref>
      <ref url="http://www.securityfocus.com/bid/45936" source="BID">45936</ref>
      <ref url="http://securitytracker.com/id?1024996" source="SECTRACK">1024996</ref>
      <ref url="http://secunia.com/advisories/43106" source="SECUNIA" adv="1">43106</ref>
      <ref url="http://secunia.com/advisories/43099" source="SECUNIA" adv="1">43099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0" edition="mr1" />
        <vers num="10.0" edition="mr1:corporate" />
        <vers num="10.0" edition="mr2" />
        <vers num="10.0" edition="mr2:corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.1.2" edition="" />
        <vers num="10.0.1.2" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate" />
        <vers num="10.1" edition="mp1" />
        <vers num="10.1" edition="mp1:corporate" />
        <vers num="10.1" edition="mr4" />
        <vers num="10.1" edition="mr4:corporate" />
        <vers num="10.1" edition="mr5" />
        <vers num="10.1" edition="mr5:corporate" />
        <vers num="10.1" edition="mr6" />
        <vers num="10.1" edition="mr6:corporate" />
        <vers num="10.1" edition="mr7" />
        <vers num="10.1" edition="mr7:corporate" />
        <vers num="10.1.0.1" edition="" />
        <vers num="10.1.0.1" edition=":corporate" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate" />
        <vers num="10.1.4.1" edition="" />
        <vers num="10.1.4.1" edition=":corporate" />
        <vers num="10.1.5" edition="" />
        <vers num="10.1.5" edition=":corporate" />
        <vers num="10.1.5.1" edition="" />
        <vers num="10.1.5.1" edition=":corporate" />
        <vers num="10.1.6" edition="" />
        <vers num="10.1.6" edition=":corporate" />
        <vers num="10.1.6.1" edition="" />
        <vers num="10.1.6.1" edition=":corporate" />
        <vers num="10.1.7" edition="" />
        <vers num="10.1.7" edition=":corporate" />
        <vers num="10.1.8" edition="" />
        <vers num="10.1.8" edition=":corporate" />
        <vers num="10.1.9" edition="" />
        <vers num="10.1.9" edition=":corporate" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":corporate" />
        <vers num="10.2" edition="mr2" />
        <vers num="10.2" edition="mr2:corporate" />
        <vers num="10.2" edition="mr3" />
        <vers num="10.2" edition="mr3:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
      <prod vendor="symantec" name="system_center">
        <vers num="10.0" />
        <vers num="10.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0111" published="2011-01-31" name="CVE-2010-0111" modified="2011-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (aka AMS or AMS2), as used in Symantec AntiVirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Center (SSC) 10.x, and Symantec Quarantine Server 3.5 and 3.6, allows remote attackers to execute arbitrary programs by sending msgsys.exe a UNC share pathname, which is used directly in a CreateProcessA (aka CreateProcess) call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64943" source="XF">symantec-intelams2-dos(64943)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64942" source="XF">symantec-intelams2-code-execution(64942)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-029" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-029</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0234" source="VUPEN" adv="1">ADV-2011-0234</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_01" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110126_01</ref>
      <ref url="http://www.securityfocus.com/bid/45935" source="BID">45935</ref>
      <ref url="http://securitytracker.com/id?1024997" source="SECTRACK">1024997</ref>
      <ref url="http://secunia.com/advisories/43106" source="SECUNIA" adv="1">43106</ref>
      <ref url="http://secunia.com/advisories/43099" source="SECUNIA" adv="1">43099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0" edition="mr1" />
        <vers num="10.0" edition="mr1:corporate" />
        <vers num="10.0" edition="mr2" />
        <vers num="10.0" edition="mr2:corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.1.2" edition="" />
        <vers num="10.0.1.2" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers num="10.1" edition="" />
        <vers num="10.1" edition=":corporate" />
        <vers num="10.1" edition="mp1" />
        <vers num="10.1" edition="mp1:corporate" />
        <vers num="10.1" edition="mr4" />
        <vers num="10.1" edition="mr4:corporate" />
        <vers num="10.1" edition="mr5" />
        <vers num="10.1" edition="mr5:corporate" />
        <vers num="10.1" edition="mr6" />
        <vers num="10.1" edition="mr6:corporate" />
        <vers num="10.1" edition="mr7" />
        <vers num="10.1" edition="mr7:corporate" />
        <vers num="10.1.0.1" edition="" />
        <vers num="10.1.0.1" edition=":corporate" />
        <vers num="10.1.4" edition="" />
        <vers num="10.1.4" edition=":corporate" />
        <vers num="10.1.4.1" edition="" />
        <vers num="10.1.4.1" edition=":corporate" />
        <vers num="10.1.5" edition="" />
        <vers num="10.1.5" edition=":corporate" />
        <vers num="10.1.5.1" edition="" />
        <vers num="10.1.5.1" edition=":corporate" />
        <vers num="10.1.6" edition="" />
        <vers num="10.1.6" edition=":corporate" />
        <vers num="10.1.6.1" edition="" />
        <vers num="10.1.6.1" edition=":corporate" />
        <vers num="10.1.7" edition="" />
        <vers num="10.1.7" edition=":corporate" />
        <vers num="10.1.8" edition="" />
        <vers num="10.1.8" edition=":corporate" />
        <vers num="10.1.9" edition="" />
        <vers num="10.1.9" edition=":corporate" />
        <vers num="10.2" edition="" />
        <vers num="10.2" edition=":corporate" />
        <vers num="10.2" edition="mr2" />
        <vers num="10.2" edition="mr2:corporate" />
        <vers num="10.2" edition="mr3" />
        <vers num="10.2" edition="mr3:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="3.5" />
        <vers num="3.6" />
      </prod>
      <prod vendor="symantec" name="system_center">
        <vers num="10.0" />
        <vers num="10.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0112" published="2010-10-28" name="CVE-2010-0112" modified="2011-01-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file; (2) unspecified parameters in a DetailReportGroup (aka DetailReportGroup.lgx) action to rdpageimlogic.aspx; the (3) selclause, (4) whereTrendTimeClause, (5) TrendTypeForReport, (6) whereProtocolClause, or (7) groupClause parameter in a SummaryReportGroup (aka SummaryReportGroup.lgx) action to rdpageimlogic.aspx; the (8) loginTimeStamp, (9) dbo, (10) dateDiffParam, or (11) whereClause parameter in a LoggedInUsers (aka LoggedInUSers.lgx) action to (a) rdpageimlogic.aspx or (b) rdPage.aspx; the (12) selclause, (13) whereTrendTimeClause, (14) TrendTypeForReport, (15) whereProtocolClause, or (16) groupClause parameter to rdpageimlogic.aspx; (17) the groupList parameter to IMAdminReportTrendFormRun.asp; or (18) the email parameter to IMAdminScheduleReport.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62806" source="XF">immanager-unspecified-sql-injection(62806)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-226/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-226/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-225/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-225/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-224/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-224/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-223/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-223/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-222/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-222/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-221/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-221/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-220/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-220/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2789" source="VUPEN" adv="1">ADV-2010-2789</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101027_01" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101027_01</ref>
      <ref url="http://www.securitytracker.com/id?1024648" source="SECTRACK">1024648</ref>
      <ref url="http://www.securityfocus.com/bid/44299" source="BID">44299</ref>
      <ref url="http://secunia.com/advisories/41959" source="SECUNIA" adv="1">41959</ref>
      <ref url="http://osvdb.org/68903" source="OSVDB">68903</ref>
      <ref url="http://osvdb.org/68902" source="OSVDB">68902</ref>
      <ref url="http://osvdb.org/68901" source="OSVDB">68901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="im_manager">
        <vers num="6.0" />
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.5" />
        <vers num="8.3" />
        <vers num="8.4.0" />
        <vers num="8.4.1" />
        <vers num="8.4.10" />
        <vers num="8.4.11" />
        <vers num="8.4.12" />
        <vers num="8.4.13" />
        <vers prev="1" num="8.4.15" />
        <vers num="8.4.2" />
        <vers num="8.4.5" />
        <vers num="8.4.6" />
        <vers num="8.4.7" />
        <vers num="8.4.8" />
        <vers num="8.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0113" published="2010-11-15" name="CVE-2010-0113" modified="2010-12-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assisted remote attackers to obtain potentially sensitive information by leveraging the ability of a separate crafted application to read these logs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/63294" source="XF">norton-mobile-setup-information-disclosure(63294)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2982" source="VUPEN" adv="1">ADV-2010-2982</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101111_00" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101111_00</ref>
      <ref url="http://www.securityfocus.com/bid/44767" source="BID">44767</ref>
      <ref url="http://osvdb.org/69253" source="OSVDB">69253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="mobile_security">
        <vers num="1.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0114" published="2010-12-21" name="CVE-2010-0114" modified="2010-12-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">fw_charts.php in the reporting module in the Manager (aka SEPM) component in Symantec Endpoint Protection (SEP) 11.x before 11 RU6 MP2 allows remote attackers to bypass intended restrictions on report generation, overwrite arbitrary PHP scripts, and execute arbitrary code via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64118" source="XF">symantec-endpoint-fwcharts-code-execution(64118)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-291/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-291/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3252" source="VUPEN" adv="1">ADV-2010-3252</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101215_00" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20101215_00</ref>
      <ref url="http://www.securityfocus.com/bid/45372" source="BID">45372</ref>
      <ref url="http://securitytracker.com/id?1024900" source="SECTRACK">1024900</ref>
      <ref url="http://secunia.com/advisories/42643" source="SECUNIA" adv="1">42643</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="11" />
        <vers num="11.0" edition="ru5" />
        <vers num="11.0" edition="ru6" />
        <vers num="11.0" edition="ru6mp1" />
        <vers num="11.0.1" edition="mp1" />
        <vers num="11.0.2" edition="mp1" />
        <vers num="11.0.2" edition="mp2" />
        <vers num="11.0.3001" />
        <vers num="11.0.4" edition="mp1a" />
        <vers num="11.0.4" edition="mp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0115" published="2011-01-14" name="CVE-2010-0115" modified="2011-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in the GUI management console in Symantec Web Gateway 4.5 before 4.5.0.376 allows remote attackers to execute arbitrary SQL commands via the USERNAME parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64658" source="XF">symantec-web-username-sql-injection(64658)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-013/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-013/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0088" source="VUPEN" adv="1">ADV-2011-0088</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110112_00" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2011&amp;suid=20110112_00</ref>
      <ref url="http://www.securitytracker.com/id?1024958" source="SECTRACK">1024958</ref>
      <ref url="http://www.securityfocus.com/bid/45742" source="BID">45742</ref>
      <ref url="http://secunia.com/advisories/42878" source="SECUNIA" adv="1">42878</ref>
      <ref url="http://osvdb.org/70415" source="OSVDB">70415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="web_gateway">
        <vers num="4.5" />
        <vers num="4.5.0.325" />
        <vers num="4.5.0.326" />
        <vers num="4.5.0.327" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0116" published="2010-08-30" name="CVE-2010-0116" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61420" source="XF">realplayer-qcp-bo(61420)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2216" source="VUPEN">ADV-2010-2216</ref>
      <ref url="http://www.securitytracker.com/id?1024370" source="SECTRACK">1024370</ref>
      <ref url="http://service.real.com/realplayer/security/08262010_player/en/" source="CONFIRM" adv="1">http://service.real.com/realplayer/security/08262010_player/en/</ref>
      <ref url="http://secunia.com/secunia_research/2010-3/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-3/</ref>
      <ref url="http://secunia.com/advisories/41154" source="SECUNIA">41154</ref>
      <ref url="http://secunia.com/advisories/41096" source="SECUNIA">41096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7326" source="OVAL">oval:org.mitre.oval:def:7326</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="realnetworks" name="realplayer_sp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0117" published="2010-08-30" name="CVE-2010-0117" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows do not properly handle dimensions during YUV420 transformations, which might allow remote attackers to execute arbitrary code via crafted MP4 content.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61421" source="XF">realplayer-yuv420-code-execution(61421)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2216" source="VUPEN">ADV-2010-2216</ref>
      <ref url="http://www.securitytracker.com/id?1024370" source="SECTRACK">1024370</ref>
      <ref url="http://service.real.com/realplayer/security/08262010_player/en/" source="CONFIRM" adv="1">http://service.real.com/realplayer/security/08262010_player/en/</ref>
      <ref url="http://secunia.com/secunia_research/2010-5/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-5/</ref>
      <ref url="http://secunia.com/advisories/41154" source="SECUNIA">41154</ref>
      <ref url="http://secunia.com/advisories/41096" source="SECUNIA">41096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7169" source="OVAL">oval:org.mitre.oval:def:7169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="realnetworks" name="realplayer_sp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0118" published="2010-02-24" name="CVE-2010-0118" modified="2010-03-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38353" source="BID">38353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509685/100/0/threaded" source="BUGTRAQ">20100222 Secunia Research: Bournal Insecure Temporary Files Security Issue</ref>
      <ref url="http://secunia.com/secunia_research/2010-6/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-6/</ref>
      <ref url="http://secunia.com/advisories/38814" source="SECUNIA">38814</ref>
      <ref url="http://secunia.com/advisories/38554" source="SECUNIA" adv="1">38554</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html" source="FEDORA">FEDORA-2010-3168</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html" source="FEDORA">FEDORA-2010-3221</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html" source="FEDORA">FEDORA-2010-3301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="becauseinter" name="bournal">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0119" published="2010-02-24" name="CVE-2010-0119" modified="2010-03-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38352" source="BID">38352</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509688/100/0/threaded" source="BUGTRAQ">20100222 Secunia Research: Bournal ccrypt Information Disclosure Security Issue</ref>
      <ref url="http://secunia.com/secunia_research/2010-7/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-7/</ref>
      <ref url="http://secunia.com/advisories/38814" source="SECUNIA">38814</ref>
      <ref url="http://secunia.com/advisories/38723" source="SECUNIA" adv="1">38723</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036764.html" source="FEDORA">FEDORA-2010-3168</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036701.html" source="FEDORA">FEDORA-2010-3221</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036697.html" source="FEDORA">FEDORA-2010-3301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="becauseinter" name="bournal">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0120" published="2010-08-30" name="CVE-2010-0120" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61422" source="XF">realplayer-qcp-audio-bo(61422)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2216" source="VUPEN">ADV-2010-2216</ref>
      <ref url="http://www.securitytracker.com/id?1024370" source="SECTRACK">1024370</ref>
      <ref url="http://service.real.com/realplayer/security/08262010_player/en/" source="CONFIRM" adv="1">http://service.real.com/realplayer/security/08262010_player/en/</ref>
      <ref url="http://secunia.com/secunia_research/2010-8/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-8/</ref>
      <ref url="http://secunia.com/advisories/41154" source="SECUNIA">41154</ref>
      <ref url="http://secunia.com/advisories/41096" source="SECUNIA">41096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6807" source="OVAL">oval:org.mitre.oval:def:6807</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
      <prod vendor="realnetworks" name="realplayer_sp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0121" published="2010-12-14" name="CVE-2010-0121" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 does not properly perform initialization, which has unspecified impact and attack vectors.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/665.html

'CWE-665: Improper Initialization'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1024861" source="SECTRACK">1024861</ref>
      <ref url="http://service.real.com/realplayer/security/12102010_player/en/" source="CONFIRM" adv="1">http://service.real.com/realplayer/security/12102010_player/en/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11.0" />
        <vers num="11.0.1" />
        <vers num="11.0.2" />
        <vers num="11.0.2.1744" />
        <vers num="11.0.3" />
        <vers num="11.0.4" />
        <vers num="11.0.5" />
        <vers num="11.1" />
        <vers num="12.0.0.1444" />
      </prod>
      <prod vendor="realnetworks" name="realplayer_sp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0122" published="2010-03-15" name="CVE-2010-0122" modified="2010-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56799" source="XF">timeclock-auth-sql-injection(56799)</ref>
      <ref url="http://www.securityfocus.com/bid/38639" source="BID">38639</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509995/100/0/threaded" source="BUGTRAQ">20100310 Secunia Research: Employee Timeclock Software SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/62832" source="OSVDB">62832</ref>
      <ref url="http://www.osvdb.org/62831" source="OSVDB">62831</ref>
      <ref url="http://secunia.com/secunia_research/2010-11/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-11/</ref>
      <ref url="http://secunia.com/advisories/38739" source="SECUNIA" adv="1">38739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timeclock-software" name="employee_timeclock_software">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0123" published="2010-03-15" name="CVE-2010-0123" modified="2010-03-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56798" source="XF">timeclock-database-info-disclosure(56798)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509990/100/0/threaded" source="BUGTRAQ">20100310 Secunia Research: Employee Timeclock Software Backup Information Disclosure</ref>
      <ref url="http://www.osvdb.org/62833" source="OSVDB">62833</ref>
      <ref url="http://secunia.com/secunia_research/2010-10/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-10/</ref>
      <ref url="http://secunia.com/advisories/38739" source="SECUNIA" adv="1">38739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timeclock-software" name="employee_timeclock_software">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0124" published="2010-03-15" name="CVE-2010-0124" modified="2010-03-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56800" source="XF">timeclock-mysqldump-info-disclosure(56800)</ref>
      <ref url="http://www.securityfocus.com/bid/38642" source="BID">38642</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509996/100/0/threaded" source="BUGTRAQ">20100310 Secunia Research: Employee Timeclock Software "mysqldump" Password Disclosure</ref>
      <ref url="http://www.osvdb.org/62830" source="OSVDB">62830</ref>
      <ref url="http://secunia.com/secunia_research/2010-12/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-12/</ref>
      <ref url="http://secunia.com/advisories/38739" source="SECUNIA" adv="1">38739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timeclock-software" name="employee_timeclock_software">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0125" published="2010-12-14" name="CVE-2010-0125" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, and Mac RealPlayer 11.0 through 12.0.0.1444 do not properly parse spectral data in AAC files, which has unspecified impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1024861" source="SECTRACK">1024861</ref>
      <ref url="http://service.real.com/realplayer/security/12102010_player/en/" source="CONFIRM" adv="1">http://service.real.com/realplayer/security/12102010_player/en/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11.0" />
        <vers num="11.0.1" />
        <vers num="11.0.2" />
        <vers num="11.0.3" />
        <vers num="11.0.4" />
        <vers num="11.0.5" />
        <vers num="11.1" />
        <vers num="12.0.0.1444" />
        <vers num="2.1.2" edition="" />
        <vers num="2.1.2" edition=":enterprise" />
      </prod>
      <prod vendor="realnetworks" name="realplayer_sp">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0126" published="2010-08-17" name="CVE-2010-0126" modified="2011-07-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted compound file, as demonstrated using a Quattro Pro file, which is not properly handled by the Quattro speed reader (qpssr.dll).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-16/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-16/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0127" published="2010-05-13" name="CVE-2010-0127" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511260/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player 3D Parsing Memory Corruption</ref>
      <ref url="http://secunia.com/secunia_research/2010-17/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-17/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7477" source="OVAL">oval:org.mitre.oval:def:7477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0128" published="2010-05-13" name="CVE-2010-0128" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511261/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player Signedness Error Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511240/100/0/threaded" source="BUGTRAQ">20100511 [CORE-2010-0405] Adobe Director Invalid Read</ref>
      <ref url="http://www.coresecurity.com/content/adobe-director-invalid-read" source="MISC">http://www.coresecurity.com/content/adobe-director-invalid-read</ref>
      <ref url="http://secunia.com/secunia_research/2010-19/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-19/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7273" source="OVAL">oval:org.mitre.oval:def:7273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="director">
        <vers num="11.0.0.426" />
        <vers prev="1" num="11.5" />
      </prod>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0129" published="2010-05-13" name="CVE-2010-0129" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=869" source="IDEFENSE" patch="1">20100511 Abobe Shockwave Player Heap Memory Indexing Vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/40082" source="BID">40082</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511262/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player Array Indexing Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511256/100/0/threaded" source="BUGTRAQ">20100512 [CAL-20100204-2]Adobe Shockwave Player Director File Parsing integer overflow vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-20/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-20/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7134" source="OVAL">oval:org.mitre.oval:def:7134</ref>
      <ref url="http://hi.baidu.com/fs_fx/blog/item/fa74a61705b5e24621a4e951.html" source="MISC">http://hi.baidu.com/fs_fx/blog/item/fa74a61705b5e24621a4e951.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0138.html" source="FULLDISC">20100511 [CAL-20100204-2]Adobe Shockwave Player Director File Parsing integer overflow vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0130" published="2010-05-13" name="CVE-2010-0130" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40084" source="BID">40084</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511263/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player Integer Overflow Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-22/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-22/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7108" source="OVAL">oval:org.mitre.oval:def:7108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0131" published="2010-08-17" name="CVE-2010-0131" modified="2011-01-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the SpreadSheet Lotus 123 reader (wkssr.dll), as used in Autonomy KeyView 10.4 and 10.9, Symantec Mail Security, and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to floating point conversion in unknown record types.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-25/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-25/</ref>
      <ref url="http://secunia.com/secunia_research/2010-23/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-23/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="symantec" name="mail_security">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0132" published="2010-03-31" name="CVE-2010-0132" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input," a different vulnerability than CVE-2010-0736.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0743" source="VUPEN" patch="1" adv="1">ADV-2010-0743</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0844" source="VUPEN">ADV-2010-0844</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510408/100/0/threaded" source="BUGTRAQ">20100330 Secunia Research: ViewVC Regular Expression Search Cross-Site Scripting</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2342&amp;r2=2359&amp;pathrev=HEAD" source="CONFIRM">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2342&amp;r2=2359&amp;pathrev=HEAD</ref>
      <ref url="http://secunia.com/secunia_research/2010-26/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-26/</ref>
      <ref url="http://secunia.com/advisories/38918" source="SECUNIA" adv="1">38918</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html" source="SUSE">SUSE-SR:2010:009</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038925.html" source="FEDORA">FEDORA-2010-5805</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038456.html" source="FEDORA">FEDORA-2010-5524</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038420.html" source="FEDORA">FEDORA-2010-5507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewvc" name="viewvc">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0133" published="2010-08-17" name="CVE-2010-0133" modified="2010-08-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allow remote attackers to execute arbitrary code via unspecified vectors related to "certain records."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-28/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-28/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0134" published="2010-08-17" name="CVE-2010-0134" modified="2010-08-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in rtfsr.dll in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted \ls keyword in a list override table entry in an RTF file, which triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-27/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-27/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0135" published="2010-08-17" name="CVE-2010-0135" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the WordPerfect 5.x reader (wosr.dll), as used in Autonomy KeyView 10.4 and 10.9 and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to "data blocks."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-31/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-31/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0136" published="2010-02-16" name="CVE-2010-0136" modified="2010-11-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/2905" source="VUPEN">ADV-2010-2905</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0635" source="VUPEN">ADV-2010-0635</ref>
      <ref url="http://www.ubuntu.com/usn/USN-903-1" source="UBUNTU">USN-903-1</ref>
      <ref url="http://www.securityfocus.com/bid/38245" source="BID">38245</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:221" source="MANDRIVA">MDVSA-2010:221</ref>
      <ref url="http://www.mail-archive.com/debian-openoffice@lists.debian.org/msg23178.html" source="MLIST">[debian-openoffice] 20100212 ./packages/openofficeorg/3.1.1/unstable r1866: merge 1:3.1.1-15+squeeze1</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1995" source="DEBIAN">DSA-1995</ref>
      <ref url="http://securitytracker.com/id?1023588" source="SECTRACK">1023588</ref>
      <ref url="http://secunia.com/advisories/38921" source="SECUNIA">38921</ref>
      <ref url="http://secunia.com/advisories/38695" source="SECUNIA">38695</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.html" source="SUSE">SUSE-SA:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="openoffice.org">
        <vers num="2.0.4" />
        <vers num="2.4.1" />
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0137" published="2010-01-21" name="CVE-2010-0137" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b13512.shtml" source="CISCO" patch="1" adv="1">20100120 Cisco IOS XR Software SSH Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55767" source="XF">ciscoios-ssh-dos(55767)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0183" source="VUPEN" adv="1">ADV-2010-0183</ref>
      <ref url="http://www.securityfocus.com/bid/37878" source="BID">37878</ref>
      <ref url="http://securitytracker.com/id?1023480" source="SECTRACK">1023480</ref>
      <ref url="http://secunia.com/advisories/38227" source="SECUNIA" adv="1">38227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0138" published="2010-01-21" name="CVE-2010-0138" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party component," aka Bug ID CSCsv62350.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55768" source="XF">cisco-ipm-corba-bo(55768)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-004/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-004/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0184" source="VUPEN" adv="1">ADV-2010-0184</ref>
      <ref url="http://www.securityfocus.com/bid/37879" source="BID">37879</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1351d.shtml" source="CISCO" adv="1">20100120 CiscoWorks Internetwork Performance Monitor CORBA GIOP Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1023484" source="SECTRACK">1023484</ref>
      <ref url="http://secunia.com/advisories/38230" source="SECUNIA" adv="1">38230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ciscoworks_internetwork_performance_monitor">
        <vers num="2.4" />
        <vers num="2.5" />
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0139" published="2010-01-28" name="CVE-2010-0139" modified="2011-01-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml" source="CISCO" patch="1" adv="1">20100127 Multiple Vulnerabilities in Cisco Unified MeetingPlace</ref>
      <ref url="http://www.securityfocus.com/bid/37965" source="BID">37965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="5" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.0.170.0" />
        <vers num="6.0.244" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0140" published="2010-01-28" name="CVE-2010-0140" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.</descript>
      <descript source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml


Affected Products
Vulnerable Products

Cisco Unified MeetingPlace versions 5, 6, and 7 are each affected by at least one of the vulnerabilities described in this document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml" source="CISCO" patch="1" adv="1">20100127 Multiple Vulnerabilities in Cisco Unified MeetingPlace</ref>
      <ref url="http://www.securityfocus.com/bid/37965" source="BID">37965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0141" published="2010-01-28" name="CVE-2010-0141" modified="2011-01-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml" source="CISCO" patch="1" adv="1">20100127 Multiple Vulnerabilities in Cisco Unified MeetingPlace</ref>
      <ref url="http://www.securityfocus.com/bid/37965" source="BID">37965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="6.0" />
        <vers num="6.0.170.0" />
        <vers num="6.0.244" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0142" published="2010-01-28" name="CVE-2010-0142" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530.</descript>
      <descript source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml


Affected Products
Vulnerable Products

Cisco Unified MeetingPlace versions 5, 6, and 7 are each affected by at least one of the vulnerabilities described in this document.

</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml" source="CISCO" patch="1" adv="1">20100127 Multiple Vulnerabilities in Cisco Unified MeetingPlace</ref>
      <ref url="http://www.securityfocus.com/bid/37965" source="BID">37965</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0143" published="2010-02-11" name="CVE-2010-0143" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65921.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b17903.shtml" source="CISCO" patch="1" adv="1">20100210 Multiple Vulnerabilities in Cisco IronPort Encryption Appliance</ref>
      <ref url="http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html</ref>
      <ref url="http://secunia.com/advisories/38525" source="SECUNIA">38525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0144" published="2010-02-11" name="CVE-2010-0144" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65922.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b17903.shtml" source="CISCO" patch="1" adv="1">20100210 Multiple Vulnerabilities in Cisco IronPort Encryption Appliance</ref>
      <ref url="http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html</ref>
      <ref url="http://secunia.com/advisories/38525" source="SECUNIA">38525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0145" published="2010-02-11" name="CVE-2010-0145" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka IronPort Bug 65923.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b17903.shtml" source="CISCO" patch="1" adv="1">20100210 Multiple Vulnerabilities in Cisco IronPort Encryption Appliance</ref>
      <ref url="http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b17904.html</ref>
      <ref url="http://secunia.com/advisories/38525" source="SECUNIA">38525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0146" published="2010-02-23" name="CVE-2010-0146" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml" source="CISCO" patch="1" adv="1">20100217 Multiple Vulnerabilities in Cisco Security Agent</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56345" source="XF">cisco-sa-mgmtcenter-dir-traversal(56345)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0416" source="VUPEN" adv="1">ADV-2010-0416</ref>
      <ref url="http://www.securitytracker.com/id?1023606" source="SECTRACK">1023606</ref>
      <ref url="http://www.securityfocus.com/bid/38271" source="BID">38271</ref>
      <ref url="http://secunia.com/advisories/38619" source="SECUNIA" adv="1">38619</ref>
      <ref url="http://osvdb.org/62443" source="OSVDB">62443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0147" published="2010-02-23" name="CVE-2010-0147" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml" source="CISCO" patch="1" adv="1">20100217 Multiple Vulnerabilities in Cisco Security Agent</ref>
      <ref url="http://secunia.com/advisories/38619" source="SECUNIA" patch="1" adv="1">38619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56346" source="XF">cisco-sa-mgmtcenter-sql-injection(56346)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0416" source="VUPEN" adv="1">ADV-2010-0416</ref>
      <ref url="http://www.securitytracker.com/id?1023606" source="SECTRACK">1023606</ref>
      <ref url="http://www.securityfocus.com/bid/38272" source="BID">38272</ref>
      <ref url="http://osvdb.org/62444" source="OSVDB">62444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0148" published="2010-02-23" name="CVE-2010-0148" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allows remote attackers to cause a denial of service (kernel panic) via "a series of TCP packets."</descript>
      <descript source="nvd">Per:  http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml

Only Cisco Security Agent release 5.2 for Linux, either managed or standalone, are affected by the DoS vulnerability (the Windows version is not affected).

The Linux version of standalone agents are installed in the following products:

    * Cisco Unified Communications Manager (CallManager)
    * IPCC Express
    * IP Interactive Voice Response (IP IVR)
    * Cisco Unified Meeting Place
    * Cisco Personal Assistant (PA)
    * Cisco Unity Connection

Note:  The Sun Solaris version of the Cisco Security Agent is not affected by these vulnerabilities. Only Cisco Security Agent release 5.2 for Linux, either managed or standalone, are affected by the DoS vulnerability. "</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml" source="CISCO" patch="1" adv="1">20100217 Multiple Vulnerabilities in Cisco Security Agent</ref>
      <ref url="http://secunia.com/advisories/38619" source="SECUNIA" patch="1" adv="1">38619</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56347" source="XF">cisco-securityagent-tcp-dos(56347)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0416" source="VUPEN" adv="1">ADV-2010-0416</ref>
      <ref url="http://www.securitytracker.com/id?1023607" source="SECTRACK">1023607</ref>
      <ref url="http://www.securityfocus.com/bid/38273" source="BID">38273</ref>
      <ref url="http://osvdb.org/62445" source="OSVDB">62445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0149" published="2010-02-19" name="CVE-2010-0149" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.46), 8.0 before 8.0(4.38), 8.1 before 8.1(2.29), and 8.2 before 8.2(1.5); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (prevention of new connections) via crafted TCP segments during termination of the TCP connection that cause the connection to remain in CLOSEWAIT status, aka "TCP Connection Exhaustion Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56336" source="XF">cisco-asa-tcp-dos(56336)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38275" source="BID">38275</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38636" source="SECUNIA" adv="1">38636</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62433" source="OSVDB">62433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0150" published="2010-02-19" name="CVE-2010-0150" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCsy91157.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56338" source="XF">cisco-asa5500-sip-dos(56338)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38277" source="BID">38277</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38636" source="SECUNIA" adv="1">38636</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62434" source="OSVDB">62434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0151" published="2010-02-19" name="CVE-2010-0151" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Client Control Protocol (SCCP) message.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910e.shtml

"All non-fixed 4.x versions of Cisco FWSM Software are affected by this vulnerability if SCCP inspection is enabled. SCCP inspection is enabled by default."</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910e.shtml" source="CISCO" patch="1" adv="1">20100217 Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" patch="1" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56333" source="XF">cisco-fwsm-asa-sccp-dos(56333)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0418" source="VUPEN">ADV-2010-0418</ref>
      <ref url="http://www.securitytracker.com/id?1023609" source="SECTRACK">1023609</ref>
      <ref url="http://www.securityfocus.com/bid/38274" source="BID">38274</ref>
      <ref url="http://secunia.com/advisories/38621" source="SECUNIA" adv="1">38621</ref>
      <ref url="http://osvdb.org/62432" source="OSVDB">62432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="4.0" />
        <vers num="4.0(4)" />
        <vers num="4.0(6)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0152" published="2010-09-14" name="CVE-2010-0152" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the userfilter parameter to pvm_user_management.php, (3) the ping parameter to sys_tools.php in a sys_ping.php action, (4) the action parameter to pvm_cert_commaction.php, (5) the action parameter to pvm_cert_serveraction.php, (6) the action parameter to pvm_smtpstore.php, (7) the l parameter to sla/index.php, or (8) unspecified stored data; and allow remote authenticated users to inject arbitrary web script or HTML via (9) saved search filters.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.ventuneac.net/security-advisories/MVSA-10-007

Affected Versions

IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)
IBM Proventia Network Mail Security System - virtual appliance (firmware 2.5)</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ventuneac.net/security-advisories/MVSA-10-007" source="MISC">http://www.ventuneac.net/security-advisories/MVSA-10-007</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513629/100/0/threaded" source="BUGTRAQ">20100912 MVSA-10-007 / CVE-2010-0152 - IBM Proventia Mail Security System - Multiple persistent and reflected XSS vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance_firmware">
        <vers num="1.6" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0153" published="2010-09-14" name="CVE-2010-0153" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct denial of service attacks.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per:

Affected Versions

IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)
IBM Proventia Network Mail Security System - virtual appliance (firmware 2.5)</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ventuneac.net/security-advisories/MVSA-10-006" source="MISC">http://www.ventuneac.net/security-advisories/MVSA-10-006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513627/100/0/threaded" source="BUGTRAQ">20100912 MVSA-10-006 / CVE-2010-0153 - IBM Proventia Network Mail Security System - Cross-Site Request Forgery vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance_firmware">
        <vers num="1.6" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0154" published="2010-09-14" name="CVE-2010-0154" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.ventuneac.net/security-advisories/MVSA-10-008

Affected Versions

IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ventuneac.net/security-advisories/MVSA-10-008" source="MISC">http://www.ventuneac.net/security-advisories/MVSA-10-008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513637/100/0/threaded" source="BUGTRAQ">20100912 MVSA-10-008 / CVE-2010-0154 - IBM Proventia Mail Security System - Insecure Direct Object Reference vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance_firmware">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0155" published="2010-09-14" name="CVE-2010-0155" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.ventuneac.net/security-advisories/MVSA-10-009

Affected Versions

IBM Proventia Network Mail Security System - virtual appliance (firmware 1.6)</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ventuneac.net/security-advisories/MVSA-10-009" source="MISC">http://www.ventuneac.net/security-advisories/MVSA-10-009</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513636/100/0/threaded" source="BUGTRAQ">20100912 MVSA-10-009 / CVE-2010-0155 - IBM Proventia Network Mail Security System - CRLF Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance_firmware">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0156" published="2010-03-03" name="CVE-2010-0156" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502881" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=502881</ref>
      <ref url="http://secunia.com/advisories/38766" source="SECUNIA" patch="1" adv="1">38766</ref>
      <ref url="http://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6cbf6087" source="MLIST" patch="1">[puppet-announce] 20100105 ANNOUNCE: Puppet 0.25.2 "Zoe" now available!</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036166.html" source="FEDORA">FEDORA-2010-1372</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036083.html" source="FEDORA">FEDORA-2010-1079</ref>
      <ref url="http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b2896d986c2" source="MLIST">[puppet-announce] 20100108 ANNOUNCE: Puppet 0.24.9 is available</ref>
    </refs>
    <vuln_soft>
      <prod vendor="puppet" name="puppet">
        <vers num="0.24.3" />
        <vers num="0.24.4" />
        <vers num="0.24.5" />
        <vers num="0.24.6" edition="rc1" />
        <vers num="0.24.6" edition="rc2" />
        <vers num="0.24.7" edition="rc2" />
        <vers num="0.24.8" edition="rc1" />
        <vers num="0.25.0" edition="beta1" />
        <vers num="0.25.0" edition="beta2" />
        <vers num="0.25.0" edition="rc1" />
        <vers num="0.25.1" edition="rc1" />
        <vers num="0.25.1" edition="rc2" />
        <vers num="0.25.2" edition="rc1" />
        <vers num="0.25.2" edition="rc2" />
        <vers num="0.25.2" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0157" published="2010-01-06" name="CVE-2010-0157" modified="2010-01-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37583" source="BID">37583</ref>
      <ref url="http://secunia.com/advisories/37896" source="SECUNIA" adv="1">37896</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlabiblestudy-lfi.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlabiblestudy-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlabiblestudy" name="com_biblestudy">
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0158" published="2010-01-06" name="CVE-2010-0158" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php.  NOTE: the vendor disputes this report, saying: "JoomlaBamboo has investigated this report, and it is incorrect.  There is no SQL injection vulnerability involving the id parameter in an article view, and there never was. JoomlaBamboo customers have no reason to be concerned about this report."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0014" source="VUPEN" adv="1">ADV-2010-0014</ref>
      <ref url="http://www.securityfocus.com/bid/37579" source="BID">37579</ref>
      <ref url="http://www.exploit-db.com/exploits/10971" source="EXPLOIT-DB">10971</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2010-February/002320.html" source="MLIST">[VIM] 20100203 Re: disputed: CVE-2010-0158 JoomlaBamboo (JB) Simpla Admin SQL injection</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2010-February/002319.html" source="MLIST">[VIM] 20100203 disputed: CVE-2010-0158 JoomlaBamboo (JB) Simpla Admin SQL injection</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlabamboo-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlabamboo-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlabamboo" name="jb_simpla">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0159" published="2010-02-22" name="CVE-2010-0159" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=534082" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=534082</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=530880" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=530880</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=528300" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=528300</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=528134" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=528134</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=527567" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=527567</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=501934" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=501934</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=467005" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=467005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56359" source="XF">mozilla-browsereng-code-execution(56359)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0650" source="VUPEN">ADV-2010-0650</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0405" source="VUPEN" adv="1">ADV-2010-0405</ref>
      <ref url="http://www.ubuntu.com/usn/USN-896-1" source="UBUNTU">USN-896-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-895-1" source="UBUNTU">USN-895-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0154.html" source="REDHAT">RHSA-2010:0154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0153.html" source="REDHAT">RHSA-2010:0153</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0113.html" source="REDHAT">RHSA-2010:0113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0112.html" source="REDHAT">RHSA-2010:0112</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:042" source="MANDRIVA">MDVSA-2010:042</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1999" source="DEBIAN">DSA-1999</ref>
      <ref url="http://secunia.com/advisories/38847" source="SECUNIA">38847</ref>
      <ref url="http://secunia.com/advisories/38772" source="SECUNIA">38772</ref>
      <ref url="http://secunia.com/advisories/38770" source="SECUNIA">38770</ref>
      <ref url="http://secunia.com/advisories/37242" source="SECUNIA" adv="1">37242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9590" source="OVAL">oval:org.mitre.oval:def:9590</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8485" source="OVAL">oval:org.mitre.oval:def:8485</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html" source="SUSE">SUSE-SA:2010:015</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036132.html" source="FEDORA">FEDORA-2010-3267</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036097.html" source="FEDORA">FEDORA-2010-3230</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html" source="FEDORA">FEDORA-2010-1727</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html" source="FEDORA">FEDORA-2010-1936</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html" source="FEDORA">FEDORA-2010-1932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers prev="1" num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers prev="1" num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers prev="1" num="2.0.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0160" published="2010-02-22" name="CVE-2010-0160" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0405" source="VUPEN" patch="1" adv="1">ADV-2010-0405</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=534051" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=534051</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=533000" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=533000</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=531222" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=531222</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56360" source="XF">mozilla-webworkers-code-execution(56360)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-046" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-046</ref>
      <ref url="http://www.ubuntu.com/usn/USN-896-1" source="UBUNTU">USN-896-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-895-1" source="UBUNTU">USN-895-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510533/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-046: Mozilla Firefox Web Worker Array Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0112.html" source="REDHAT">RHSA-2010:0112</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-02.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:042" source="MANDRIVA">MDVSA-2010:042</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1999" source="DEBIAN">DSA-1999</ref>
      <ref url="http://secunia.com/advisories/38847" source="SECUNIA">38847</ref>
      <ref url="http://secunia.com/advisories/37242" source="SECUNIA" adv="1">37242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8465" source="OVAL">oval:org.mitre.oval:def:8465</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11166" source="OVAL">oval:org.mitre.oval:def:11166</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html" source="SUSE">SUSE-SA:2010:015</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html" source="FEDORA">FEDORA-2010-1727</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html" source="FEDORA">FEDORA-2010-1936</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html" source="FEDORA">FEDORA-2010-1932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers prev="1" num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers prev="1" num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0161" published="2010-03-22" name="CVE-2010-0161" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=511806" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=511806</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0648" source="VUPEN" patch="1" adv="1">ADV-2010-0648</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-07.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56992" source="XF">thunderbird-activedirectory-dos(56992)</ref>
      <ref url="http://www.securityfocus.com/bid/38831" source="BID">38831</ref>
      <ref url="http://secunia.com/advisories/39001" source="SECUNIA" adv="1">39001</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14159" source="OVAL">oval:org.mitre.oval:def:14159</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers prev="1" num="1.1.18" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers prev="1" num="2.0.0.23" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0162" published="2010-02-22" name="CVE-2010-0162" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=455472" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=455472</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56363" source="XF">mozilla-svg-xss(56363)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0405" source="VUPEN" adv="1">ADV-2010-0405</ref>
      <ref url="http://www.ubuntu.com/usn/USN-896-1" source="UBUNTU">USN-896-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-895-1" source="UBUNTU">USN-895-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0112.html" source="REDHAT">RHSA-2010:0112</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-05.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:042" source="MANDRIVA">MDVSA-2010:042</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1999" source="DEBIAN">DSA-1999</ref>
      <ref url="http://secunia.com/advisories/38847" source="SECUNIA">38847</ref>
      <ref url="http://secunia.com/advisories/37242" source="SECUNIA" adv="1">37242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8631" source="OVAL">oval:org.mitre.oval:def:8631</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10697" source="OVAL">oval:org.mitre.oval:def:10697</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html" source="SUSE">SUSE-SA:2010:015</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html" source="FEDORA">FEDORA-2010-1727</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html" source="FEDORA">FEDORA-2010-1936</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html" source="FEDORA">FEDORA-2010-1932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0163" published="2010-03-22" name="CVE-2010-0163" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=505221" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=505221</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-07.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56993" source="XF">thunderbird-messages-dos(56993)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1556" source="VUPEN">ADV-2010-1556</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0648" source="VUPEN" adv="1">ADV-2010-0648</ref>
      <ref url="http://www.ubuntu.com/usn/USN-915-1" source="UBUNTU">USN-915-1</ref>
      <ref url="http://www.securityfocus.com/bid/38831" source="BID">38831</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0499.html" source="REDHAT">RHSA-2010:0499</ref>
      <ref url="http://secunia.com/advisories/39001" source="SECUNIA" adv="1">39001</ref>
      <ref url="http://secunia.com/advisories/38977" source="SECUNIA">38977</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14259" source="OVAL">oval:org.mitre.oval:def:14259</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10805" source="OVAL">oval:org.mitre.oval:def:10805</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers prev="1" num="1.1.18" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers prev="1" num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0164" published="2010-03-25" name="CVE-2010-0164" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=547143" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=547143</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-047" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-047</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38921" source="BID">38921</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510535/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-047: Mozilla Firefox libpr0n imgContainer Bits-Per-Pixel Change Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-09.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-09.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8703" source="OVAL">oval:org.mitre.oval:def:8703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0165" published="2010-03-25" name="CVE-2010-0165" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=542849" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=542849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-11.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8472" source="OVAL">oval:org.mitre.oval:def:8472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0166" published="2010-03-25" name="CVE-2010-0166" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=538065" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=538065</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38943" source="BID">38943</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-11.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14182" source="OVAL">oval:org.mitre.oval:def:14182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0167" published="2010-03-25" name="CVE-2010-0167" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-11.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2010/mfsa2010-11.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=535641" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=535641</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=534082" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=534082</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38944" source="BID">38944</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9835" source="OVAL">oval:org.mitre.oval:def:9835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8610" source="OVAL">oval:org.mitre.oval:def:8610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers prev="1" num="2.0.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0168" published="2010-03-25" name="CVE-2010-0168" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID" patch="1">38918</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=540642" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=540642</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-13.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-13.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8711" source="OVAL">oval:org.mitre.oval:def:8711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
        <vers num="3.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0169" published="2010-03-25" name="CVE-2010-0169" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=535806" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=535806</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-14.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8431" source="OVAL">oval:org.mitre.oval:def:8431</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11391" source="OVAL">oval:org.mitre.oval:def:11391</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers prev="1" num="2.0.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0170" published="2010-03-25" name="CVE-2010-0170" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=541530" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=541530</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38919" source="BID">38919</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-10.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-10.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8602" source="OVAL">oval:org.mitre.oval:def:8602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0171" published="2010-03-25" name="CVE-2010-0171" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID" patch="1">38918</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-12.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2010/mfsa2010-12.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=531364" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=531364</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7743" source="OVAL">oval:org.mitre.oval:def:7743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10773" source="OVAL">oval:org.mitre.oval:def:10773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers prev="1" num="2.0.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0172" published="2010-03-25" name="CVE-2010-0172" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-15.html" source="CONFIRM" patch="1">http://www.mozilla.org/security/announce/2010/mfsa2010-15.html</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=537862" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=537862</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0692" source="VUPEN">ADV-2010-0692</ref>
      <ref url="http://www.securityfocus.com/bid/38918" source="BID">38918</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8281" source="OVAL">oval:org.mitre.oval:def:8281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0173" published="2010-04-05" name="CVE-2010-0173" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=542136" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=542136</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=499862" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=499862</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=496011" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=496011</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=491722" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=491722</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=488850" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=488850</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57388" source="XF">firefox-browser-eng-code-execution(57388)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-16.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-16.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023781" source="SECTRACK">1023781</ref>
      <ref url="http://securitytracker.com/id?1023775" source="SECTRACK">1023775</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39242" source="SECUNIA" adv="1">39242</ref>
      <ref url="http://secunia.com/advisories/39204" source="SECUNIA" adv="1">39204</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7467" source="OVAL">oval:org.mitre.oval:def:7467</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html" source="FEDORA">FEDORA-2010-5539</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html" source="FEDORA">FEDORA-2010-5526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0174" published="2010-04-05" name="CVE-2010-0174" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=546530" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=546530</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=499844" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=499844</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57389" source="XF">mozilla-browser-eng-code-exec(57389)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0790" source="VUPEN">ADV-2010-0790</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0765" source="VUPEN" adv="1">ADV-2010-0765</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN">ADV-2010-0748</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0333.html" source="REDHAT">RHSA-2010:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-16.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-16.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023781" source="SECTRACK">1023781</ref>
      <ref url="http://securitytracker.com/id?1023775" source="SECTRACK">1023775</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39242" source="SECUNIA">39242</ref>
      <ref url="http://secunia.com/advisories/39240" source="SECUNIA">39240</ref>
      <ref url="http://secunia.com/advisories/39204" source="SECUNIA" adv="1">39204</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA">39136</ref>
      <ref url="http://secunia.com/advisories/39117" source="SECUNIA" adv="1">39117</ref>
      <ref url="http://secunia.com/advisories/38566" source="SECUNIA">38566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9502" source="OVAL">oval:org.mitre.oval:def:9502</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7615" source="OVAL">oval:org.mitre.oval:def:7615</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.html" source="FEDORA">FEDORA-2010-5561</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html" source="FEDORA">FEDORA-2010-5539</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html" source="FEDORA">FEDORA-2010-5526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0175" published="2010-04-05" name="CVE-2010-0175" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=540100" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=540100</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=375928" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=375928</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57390" source="XF">firefox-nstreeselection-code-execution(57390)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-050" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-050</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0790" source="VUPEN">ADV-2010-0790</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0765" source="VUPEN" adv="1">ADV-2010-0765</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN" adv="1">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510542/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-050: Mozilla Firefox nsTreeSelection EventListener Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0333.html" source="REDHAT">RHSA-2010:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-17.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-17.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023782" source="SECTRACK">1023782</ref>
      <ref url="http://securitytracker.com/id?1023780" source="SECTRACK">1023780</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39242" source="SECUNIA" adv="1">39242</ref>
      <ref url="http://secunia.com/advisories/39240" source="SECUNIA" adv="1">39240</ref>
      <ref url="http://secunia.com/advisories/39204" source="SECUNIA" adv="1">39204</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://secunia.com/advisories/39117" source="SECUNIA" adv="1">39117</ref>
      <ref url="http://secunia.com/advisories/38566" source="SECUNIA" adv="1">38566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9834" source="OVAL">oval:org.mitre.oval:def:9834</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7546" source="OVAL">oval:org.mitre.oval:def:7546</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.html" source="FEDORA">FEDORA-2010-5561</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html" source="FEDORA">FEDORA-2010-5539</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html" source="FEDORA">FEDORA-2010-5526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers prev="1" num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0176" published="2010-04-05" name="CVE-2010-0176" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execute arbitrary code via unspecified vectors that trigger access to deleted elements, related to a "dangling pointer vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=538308" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=538308</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57392" source="XF">firefox-nstreecontentview-code-exec(57392)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0790" source="VUPEN">ADV-2010-0790</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0765" source="VUPEN" adv="1">ADV-2010-0765</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN" adv="1">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0333.html" source="REDHAT">RHSA-2010:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-18.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-18.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023782" source="SECTRACK">1023782</ref>
      <ref url="http://securitytracker.com/id?1023776" source="SECTRACK">1023776</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39242" source="SECUNIA" adv="1">39242</ref>
      <ref url="http://secunia.com/advisories/39240" source="SECUNIA" adv="1">39240</ref>
      <ref url="http://secunia.com/advisories/39204" source="SECUNIA" adv="1">39204</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://secunia.com/advisories/39117" source="SECUNIA" adv="1">39117</ref>
      <ref url="http://secunia.com/advisories/38566" source="SECUNIA" adv="1">38566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7222" source="OVAL">oval:org.mitre.oval:def:7222</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11052" source="OVAL">oval:org.mitre.oval:def:11052</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038406.html" source="FEDORA">FEDORA-2010-5561</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038378.html" source="FEDORA">FEDORA-2010-5539</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038367.html" source="FEDORA">FEDORA-2010-5526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0177" published="2010-04-05" name="CVE-2010-0177" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to a "dangling pointer vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=538310" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=538310</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57393" source="XF">firefox-nspluginarray-code-execution(57393)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-049" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-049</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0765" source="VUPEN" adv="1">ADV-2010-0765</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN" adv="1">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510540/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-049: Mozilla Firefox PluginArray nsMimeType Dangling Pointer Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0333.html" source="REDHAT">RHSA-2010:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-19.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-19.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023776" source="SECTRACK">1023776</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39240" source="SECUNIA" adv="1">39240</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://secunia.com/advisories/39117" source="SECUNIA" adv="1">39117</ref>
      <ref url="http://secunia.com/advisories/38566" source="SECUNIA" adv="1">38566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7622" source="OVAL">oval:org.mitre.oval:def:7622</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10833" source="OVAL">oval:org.mitre.oval:def:10833</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers prev="1" num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0178" published="2010-04-05" name="CVE-2010-0178" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=546909" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=546909</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57391" source="XF">firefox-draganddrop-code-execution(57391)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN" adv="1">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN">ADV-2010-0748</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-20.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-20.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://securitytracker.com/id?1023776" source="SECTRACK">1023776</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://secunia.com/advisories/39240" source="SECUNIA" adv="1">39240</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6975" source="OVAL">oval:org.mitre.oval:def:6975</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10460" source="OVAL">oval:org.mitre.oval:def:10460</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0179" published="2010-04-05" name="CVE-2010-0179" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=504021" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=504021</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57394" source="XF">firefox-firebug-code-execution(57394)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0030" source="VUPEN">ADV-2011-0030</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN" adv="1">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0781" source="VUPEN" adv="1">ADV-2010-0781</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0764" source="VUPEN" adv="1">ADV-2010-0764</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.securityfocus.com/bid/39124" source="BID">39124</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0332.html" source="REDHAT">RHSA-2010:0332</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-21.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-21.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:251" source="MANDRIVA">MDVSA-2010:251</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2027" source="DEBIAN">DSA-2027</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100124650" source="CONFIRM">http://support.avaya.com/css/P8/documents/100124650</ref>
      <ref url="http://securitytracker.com/id?1023783" source="SECTRACK" adv="1">1023783</ref>
      <ref url="http://secunia.com/advisories/42818" source="SECUNIA">42818</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA" adv="1">39397</ref>
      <ref url="http://secunia.com/advisories/39308" source="SECUNIA" adv="1">39308</ref>
      <ref url="http://secunia.com/advisories/39243" source="SECUNIA" adv="1">39243</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9446" source="OVAL">oval:org.mitre.oval:def:9446</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6971" source="OVAL">oval:org.mitre.oval:def:6971</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00002.html" source="SUSE">SUSE-SA:2011:003</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers prev="1" num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers prev="1" num="2.0.2" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0180" published="2010-06-28" name="CVE-2010-0180" modified="2010-06-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=561797" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=561797</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1595" source="VUPEN" adv="1">ADV-2010-1595</ref>
      <ref url="http://www.securityfocus.com/bid/41144" source="BID">41144</ref>
      <ref url="http://www.bugzilla.org/security/3.2.6/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.2.6/</ref>
      <ref url="http://secunia.com/advisories/40300" source="SECUNIA" adv="1">40300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.6" />
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0181" published="2010-04-05" name="CVE-2010-0181" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=452093" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=452093</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57395" source="XF">firefox-mailto-weak-security(57395)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-23.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-23.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://secunia.com/advisories/39136" source="SECUNIA" adv="1">39136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6776" source="OVAL">oval:org.mitre.oval:def:6776</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0182" published="2010-04-05" name="CVE-2010-0182" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=490790" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=490790</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57396" source="XF">firefox-xmldocumentload-weak-security(57396)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0849" source="VUPEN">ADV-2010-0849</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0748" source="VUPEN" adv="1">ADV-2010-0748</ref>
      <ref url="http://www.securityfocus.com/bid/39479" source="BID">39479</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-24.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-24.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://ubuntu.com/usn/usn-921-1" source="UBUNTU">USN-921-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/39397" source="SECUNIA">39397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9375" source="OVAL">oval:org.mitre.oval:def:9375</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7618" source="OVAL">oval:org.mitre.oval:def:7618</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
        <vers num="3.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
        <vers num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0183" published="2010-06-24" name="CVE-2010-0183" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=557174" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=557174</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-27.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-27.html</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12586" source="OVAL">oval:org.mitre.oval:def:12586</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0184" published="2010-01-14" name="CVE-2010-0184" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0128" source="VUPEN" adv="1">ADV-2010-0128</ref>
      <ref url="http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt" source="CONFIRM">http://www.tibco.com/multimedia/security_advisory_runtime_agent_20100113_tcm8-10392.txt</ref>
      <ref url="http://www.tibco.com/mk/advisory.jsp" source="CONFIRM" adv="1">http://www.tibco.com/mk/advisory.jsp</ref>
      <ref url="http://www.securityfocus.com/bid/37805" source="BID">37805</ref>
      <ref url="http://secunia.com/advisories/38191" source="SECUNIA" adv="1">38191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tibco" name="runtime_agent">
        <vers num="5.4.0" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.6" />
        <vers prev="1" num="5.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0185" published="2010-02-03" name="CVE-2010-0185" modified="2010-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55997" source="XF">coldfusion-solr-information-disclosure(55997)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0259" source="VUPEN" adv="1">ADV-2010-0259</ref>
      <ref url="http://www.securitytracker.com/id?1023519" source="SECTRACK">1023519</ref>
      <ref url="http://www.securityfocus.com/bid/38007" source="BID">38007</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-04.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-04.html</ref>
      <ref url="http://secunia.com/advisories/38387" source="SECUNIA" adv="1">38387</ref>
      <ref url="http://osvdb.org/62037" source="OSVDB">62037</ref>
      <ref url="http://kb2.adobe.com/cps/807/cpsid_80719.html" source="CONFIRM">http://kb2.adobe.com/cps/807/cpsid_80719.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0186" published="2010-02-15" name="CVE-2010-0186" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-07.html


A critical vulnerability has been identified in Adobe Reader 9.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3 for Windows and Macintosh, and Adobe Reader 8.2 and Acrobat 8.2 for Windows and Macintosh. As described in Security Bulletin APSB10-06, this vulnerability (CVE-2010-0186) could subvert the domain sandbox and make unauthorized cross-domain requests.



Affected software versions

Adobe Reader 9.3 and earlier versions for Windows, Macintosh, and UNIX
Adobe Acrobat 9.3 and earlier versions for Windows and Macintosh</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-07.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-06.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-06.html</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0103.html" source="REDHAT">RHSA-2010:0103</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0102.html" source="REDHAT">RHSA-2010:0102</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=563819" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=563819</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0192" source="VUPEN">ADV-2011-0192</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/38198" source="BID">38198</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0114.html" source="REDHAT">RHSA-2010:0114</ref>
      <ref url="http://www.osvdb.org/62300" source="OSVDB">62300</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1023585" source="SECTRACK">1023585</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-09.xml" source="GENTOO">GLSA-201101-09</ref>
      <ref url="http://secunia.com/advisories/43026" source="SECUNIA">43026</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38639" source="SECUNIA" adv="1">38639</ref>
      <ref url="http://secunia.com/advisories/38547" source="SECUNIA" adv="1">38547</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8518" source="OVAL">oval:org.mitre.oval:def:8518</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers prev="1" num="9.3" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers prev="1" num="9.3" />
      </prod>
      <prod vendor="adobe" name="adobe_air">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers prev="1" num="1.5.3.9120" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.12.10" />
        <vers num="10.0.12.36" />
        <vers num="10.0.15.3" />
        <vers num="10.0.22.87" />
        <vers num="10.0.32.18" />
        <vers prev="1" num="10.0.42.34" />
        <vers num="6.0.21.0" />
        <vers num="6.0.79" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8" />
        <vers num="8.0" />
        <vers num="8.0.22.0" />
        <vers num="8.0.24.0" />
        <vers num="8.0.33.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="8.0.42.0" />
        <vers num="9" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.125.0" />
        <vers num="9.0.151.0" />
        <vers num="9.0.152.0" />
        <vers num="9.0.159.0" />
        <vers num="9.0.16" />
        <vers num="9.0.18d60" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.246.0" />
        <vers num="9.0.260.0" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="9.125.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0187" published="2010-02-15" name="CVE-2010-0187" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0102.html" source="REDHAT">RHSA-2010:0102</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=564287" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=564287</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0192" source="VUPEN">ADV-2011-0192</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/38200" source="BID">38200</ref>
      <ref url="http://www.exploit-db.com/exploits/11182" source="EXPLOIT-DB">11182</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-06.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-06.html</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1023585" source="SECTRACK">1023585</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-09.xml" source="GENTOO">GLSA-201101-09</ref>
      <ref url="http://secunia.com/advisories/43026" source="SECUNIA">43026</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38547" source="SECUNIA">38547</ref>
      <ref url="http://sebug.net/exploit/18967/" source="MISC">http://sebug.net/exploit/18967/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8393" source="OVAL">oval:org.mitre.oval:def:8393</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="adobe_air">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers prev="1" num="1.5.3.9120" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.12.10" />
        <vers num="10.0.12.36" />
        <vers num="10.0.15.3" />
        <vers num="10.0.22.87" />
        <vers num="10.0.32.18" />
        <vers prev="1" num="10.0.42.34" />
        <vers num="6.0.21.0" />
        <vers num="6.0.79" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8" />
        <vers num="8.0" />
        <vers num="8.0.22.0" />
        <vers num="8.0.24.0" />
        <vers num="8.0.33.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="8.0.42.0" />
        <vers num="9" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.125.0" />
        <vers num="9.0.151.0" />
        <vers num="9.0.152.0" />
        <vers num="9.0.159.0" />
        <vers num="9.0.16" />
        <vers num="9.0.18d60" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.246.0" />
        <vers num="9.0.260.0" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="9.125.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0188" published="2010-02-22" name="CVE-2010-0188" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56297" source="XF">adobe-unspec-priv-escalation(56297)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0399" source="VUPEN" adv="1">ADV-2010-0399</ref>
      <ref url="http://www.securityfocus.com/bid/38195" source="BID">38195</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0114.html" source="REDHAT" adv="1">RHSA-2010:0114</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-07.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-07.html</ref>
      <ref url="http://securitytracker.com/id?1023601" source="SECTRACK">1023601</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38639" source="SECUNIA" adv="1">38639</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8697" source="OVAL">oval:org.mitre.oval:def:8697</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0189" published="2010-02-23" name="CVE-2010-0189" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.</descript>
      <descript source="nvd">Per: http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html



"Adobe is aware of the recently posted report of a remote code execution vulnerability in the Adobe Download Manager."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-08.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-08.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56370" source="XF">adobe-dlmanager-unspecified-file-download(56370)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0459" source="VUPEN" adv="1">ADV-2010-0459</ref>
      <ref url="http://www.securityfocus.com/bid/38313" source="BID">38313</ref>
      <ref url="http://www.osvdb.org/62547" source="OSVDB">62547</ref>
      <ref url="http://www.akitasecurity.nl/advisory.php?id=AK20090401" source="MISC">http://www.akitasecurity.nl/advisory.php?id=AK20090401</ref>
      <ref url="http://securitytracker.com/id?1023651" source="SECTRACK">1023651</ref>
      <ref url="http://secunia.com/advisories/38729" source="SECUNIA" adv="1">38729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7182" source="OVAL">oval:org.mitre.oval:def:7182</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856" source="IDEFENSE">20100223 Multiple Vendor NOS Microsystems getPlus Downloader Input Validation Vulnerability</ref>
      <ref url="http://blogs.zdnet.com/security/?p=5505" source="MISC">http://blogs.zdnet.com/security/?p=5505</ref>
      <ref url="http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html" source="MISC">http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html</ref>
      <ref url="http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx" source="MISC">http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="download_manager">
        <vers prev="1" num="1.6.2.60" />
      </prod>
      <prod vendor="nos_microsystems" name="getplus_download_manager">
        <vers num="1.5.2.35" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0190" published="2010-04-14" name="CVE-2010-0190" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6986" source="OVAL">oval:org.mitre.oval:def:6986</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0191" published="2010-04-14" name="CVE-2010-0191" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6729" source="OVAL">oval:org.mitre.oval:def:6729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0192" published="2010-04-14" name="CVE-2010-0192" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7046" source="OVAL">oval:org.mitre.oval:def:7046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0193" published="2010-04-14" name="CVE-2010-0193" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57701" source="XF">adobe-acrobat-unspec-code-exec(57701)</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7352" source="OVAL">oval:org.mitre.oval:def:7352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0194" published="2010-04-14" name="CVE-2010-0194" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6823" source="OVAL">oval:org.mitre.oval:def:6823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0195" published="2010-04-14" name="CVE-2010-0195" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7420" source="OVAL">oval:org.mitre.oval:def:7420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0196" published="2010-04-14" name="CVE-2010-0196" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7064" source="OVAL">oval:org.mitre.oval:def:7064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0197" published="2010-04-14" name="CVE-2010-0197" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7298" source="OVAL">oval:org.mitre.oval:def:7298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0198" published="2010-04-14" name="CVE-2010-0198" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0199, CVE-2010-0202, and CVE-2010-0203.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7106" source="OVAL">oval:org.mitre.oval:def:7106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0199" published="2010-04-14" name="CVE-2010-0199" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6900" source="OVAL">oval:org.mitre.oval:def:6900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-0200" reject="1" published="2010-04-14" name="CVE-2010-0200" modified="2010-04-15">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0200.  Reason: This candidate is a duplicate of CVE-2010-0200.  Notes: All CVE users should reference CVE-2010-0200 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <range>
      <network />
    </range>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-0201" published="2010-04-14" name="CVE-2010-0201" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7056" source="OVAL">oval:org.mitre.oval:def:7056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0202" published="2010-04-14" name="CVE-2010-0202" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6733" source="OVAL">oval:org.mitre.oval:def:6733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0203" published="2010-04-14" name="CVE-2010-0203" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7494" source="OVAL">oval:org.mitre.oval:def:7494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0204" published="2010-04-14" name="CVE-2010-0204" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" patch="1" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57711" source="XF">acrobat-unspec-code-execution(57711)</ref>
      <ref url="http://www.securityfocus.com/bid/39522" source="BID">39522</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7387" source="OVAL">oval:org.mitre.oval:def:7387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0205" published="2010-03-03" name="CVE-2010-0205" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The png_decompress_chunk function in pngrutil.c in libpng 1.0.x before 1.0.53, 1.2.x before 1.2.43, and 1.4.x before 1.4.1 does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application hang) via a crafted PNG file, as demonstrated by use of the deflate compression method on data composed of many occurrences of the same character, related to a "decompression bomb" attack.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/576029" source="CERT-VN">VU#576029</ref>
      <ref url="http://www.securityfocus.com/bid/38478" source="BID" patch="1">38478</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56661" source="XF">libpng-pngdecompresschunk-dos(56661)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2491" source="VUPEN">ADV-2010-2491</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0847" source="VUPEN">ADV-2010-0847</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0686" source="VUPEN">ADV-2010-0686</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0682" source="VUPEN">ADV-2010-0682</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0667" source="VUPEN">ADV-2010-0667</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0637" source="VUPEN">ADV-2010-0637</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0626" source="VUPEN">ADV-2010-0626</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0605" source="VUPEN">ADV-2010-0605</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0517" source="VUPEN">ADV-2010-0517</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0014.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0014.html</ref>
      <ref url="http://www.securitytracker.com/id?1023674" source="SECTRACK">1023674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:064" source="MANDRIVA">MDVSA-2010:064</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:063" source="MANDRIVA">MDVSA-2010:063</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2032" source="DEBIAN">DSA-2032</ref>
      <ref url="http://ubuntu.com/usn/usn-913-1" source="UBUNTU">USN-913-1</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/41574" source="SECUNIA">41574</ref>
      <ref url="http://secunia.com/advisories/39251" source="SECUNIA">39251</ref>
      <ref url="http://secunia.com/advisories/38774" source="SECUNIA">38774</ref>
      <ref url="http://osvdb.org/62670" source="OSVDB">62670</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000105.html" source="MLIST">[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037607.html" source="FEDORA">FEDORA-2010-4683</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037364.html" source="FEDORA">FEDORA-2010-3414</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037355.html" source="FEDORA">FEDORA-2010-3375</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037237.html" source="FEDORA">FEDORA-2010-2988</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://libpng.sourceforge.net/decompression_bombs.html" source="CONFIRM">http://libpng.sourceforge.net/decompression_bombs.html</ref>
      <ref url="http://libpng.sourceforge.net/ADVISORY-1.4.1.html" source="CONFIRM" adv="1">http://libpng.sourceforge.net/ADVISORY-1.4.1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libpng" name="libpng">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" edition="beta1" />
        <vers num="1.0.10" edition="rc1" />
        <vers num="1.0.11" edition="beta1" />
        <vers num="1.0.11" edition="beta2" />
        <vers num="1.0.11" edition="beta3" />
        <vers num="1.0.11" edition="rc1" />
        <vers num="1.0.12" edition="beta1" />
        <vers num="1.0.12" edition="rc1" />
        <vers num="1.0.13" />
        <vers num="1.0.14" />
        <vers num="1.0.15" edition="rc1" />
        <vers num="1.0.15" edition="rc2" />
        <vers num="1.0.15" edition="rc3" />
        <vers num="1.0.16" />
        <vers num="1.0.17" edition="rc1" />
        <vers num="1.0.18" />
        <vers num="1.0.19" edition="rc1" />
        <vers num="1.0.19" edition="rc2" />
        <vers num="1.0.19" edition="rc3" />
        <vers num="1.0.19" edition="rc5" />
        <vers num="1.0.2" />
        <vers num="1.0.20" />
        <vers num="1.0.21" edition="rc1" />
        <vers num="1.0.21" edition="rc2" />
        <vers num="1.0.22" edition="rc1" />
        <vers num="1.0.23" edition="rc1" />
        <vers num="1.0.23" edition="rc2" />
        <vers num="1.0.23" edition="rc3" />
        <vers num="1.0.23" edition="rc4" />
        <vers num="1.0.23" edition="rc5" />
        <vers num="1.0.24" edition="rc1" />
        <vers num="1.0.25" edition="rc1" />
        <vers num="1.0.25" edition="rc2" />
        <vers num="1.0.26" />
        <vers num="1.0.27" edition="rc1" />
        <vers num="1.0.27" edition="rc2" />
        <vers num="1.0.27" edition="rc3" />
        <vers num="1.0.27" edition="rc4" />
        <vers num="1.0.27" edition="rc5" />
        <vers num="1.0.27" edition="rc6" />
        <vers num="1.0.28" edition="rc2" />
        <vers num="1.0.28" edition="rc3" />
        <vers num="1.0.28" edition="rc4" />
        <vers num="1.0.28" edition="rc5" />
        <vers num="1.0.28" edition="rc6" />
        <vers num="1.0.29" edition="beta1" />
        <vers num="1.0.29" edition="rc1" />
        <vers num="1.0.29" edition="rc2" />
        <vers num="1.0.29" edition="rc3" />
        <vers num="1.0.3" />
        <vers num="1.0.30" edition="rc1" />
        <vers num="1.0.31" edition="rc01" />
        <vers num="1.0.32" />
        <vers num="1.0.33" />
        <vers num="1.0.34" />
        <vers num="1.0.35" />
        <vers num="1.0.37" />
        <vers num="1.0.38" />
        <vers num="1.0.39" />
        <vers num="1.0.40" />
        <vers num="1.0.41" />
        <vers num="1.0.42" />
        <vers num="1.0.43" />
        <vers num="1.0.44" />
        <vers num="1.0.45" />
        <vers num="1.0.46" />
        <vers num="1.0.47" />
        <vers num="1.0.48" />
        <vers num="1.0.5" />
        <vers num="1.0.50" />
        <vers num="1.0.51" />
        <vers num="1.0.52" />
        <vers num="1.0.6" edition="a" />
        <vers num="1.0.6" edition="d" />
        <vers num="1.0.6" edition="e" />
        <vers num="1.0.6" edition="f" />
        <vers num="1.0.6" edition="g" />
        <vers num="1.0.6" edition="h" />
        <vers num="1.0.6" edition="i" />
        <vers num="1.0.6" edition="j" />
        <vers num="1.0.7" edition="beta11" />
        <vers num="1.0.7" edition="beta12" />
        <vers num="1.0.7" edition="beta13" />
        <vers num="1.0.7" edition="beta14" />
        <vers num="1.0.7" edition="beta15" />
        <vers num="1.0.7" edition="beta16" />
        <vers num="1.0.7" edition="beta17" />
        <vers num="1.0.7" edition="beta18" />
        <vers num="1.0.7" edition="rc1" />
        <vers num="1.0.7" edition="rc2" />
        <vers num="1.0.8" edition="beta1" />
        <vers num="1.0.8" edition="beta2" />
        <vers num="1.0.8" edition="beta3" />
        <vers num="1.0.8" edition="beta4" />
        <vers num="1.0.8" edition="rc1" />
        <vers num="1.0.9" edition="beta1" />
        <vers num="1.0.9" edition="beta10" />
        <vers num="1.0.9" edition="beta2" />
        <vers num="1.0.9" edition="beta3" />
        <vers num="1.0.9" edition="beta4" />
        <vers num="1.0.9" edition="beta5" />
        <vers num="1.0.9" edition="beta6" />
        <vers num="1.0.9" edition="beta7" />
        <vers num="1.0.9" edition="beta8" />
        <vers num="1.0.9" edition="beta9" />
        <vers num="1.0.9" edition="rc1" />
        <vers num="1.0.9" edition="rc2" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="beta5" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" edition="beta1" />
        <vers num="1.2.1" edition="beta2" />
        <vers num="1.2.1" edition="beta3" />
        <vers num="1.2.1" edition="beta4" />
        <vers num="1.2.1" edition="rc1" />
        <vers num="1.2.1" edition="rc2" />
        <vers num="1.2.10" edition="beta1" />
        <vers num="1.2.10" edition="beta2" />
        <vers num="1.2.10" edition="beta3" />
        <vers num="1.2.10" edition="beta4" />
        <vers num="1.2.10" edition="beta5" />
        <vers num="1.2.10" edition="beta6" />
        <vers num="1.2.10" edition="beta7" />
        <vers num="1.2.10" edition="rc1" />
        <vers num="1.2.10" edition="rc2" />
        <vers num="1.2.10" edition="rc3" />
        <vers num="1.2.11" edition="beta1" />
        <vers num="1.2.11" edition="beta2" />
        <vers num="1.2.11" edition="beta3" />
        <vers num="1.2.11" edition="beta4" />
        <vers num="1.2.11" edition="rc1" />
        <vers num="1.2.11" edition="rc2" />
        <vers num="1.2.11" edition="rc3" />
        <vers num="1.2.11" edition="rc5" />
        <vers num="1.2.13" edition="beta1" />
        <vers num="1.2.13" edition="rc1" />
        <vers num="1.2.13" edition="rc2" />
        <vers num="1.2.14" edition="beta1" />
        <vers num="1.2.14" edition="beta2" />
        <vers num="1.2.14" edition="rc1" />
        <vers num="1.2.15" edition="beta1" />
        <vers num="1.2.15" edition="beta2" />
        <vers num="1.2.15" edition="beta3" />
        <vers num="1.2.15" edition="beta4" />
        <vers num="1.2.15" edition="beta5" />
        <vers num="1.2.15" edition="beta6" />
        <vers num="1.2.15" edition="rc1" />
        <vers num="1.2.15" edition="rc2" />
        <vers num="1.2.15" edition="rc3" />
        <vers num="1.2.15" edition="rc4" />
        <vers num="1.2.15" edition="rc5" />
        <vers num="1.2.16" edition="beta1" />
        <vers num="1.2.16" edition="beta2" />
        <vers num="1.2.16" edition="rc1" />
        <vers num="1.2.17" edition="beta1" />
        <vers num="1.2.17" edition="beta2" />
        <vers num="1.2.17" edition="rc1" />
        <vers num="1.2.17" edition="rc2" />
        <vers num="1.2.17" edition="rc3" />
        <vers num="1.2.17" edition="rc4" />
        <vers num="1.2.18" />
        <vers num="1.2.19" edition="beta1" />
        <vers num="1.2.19" edition="beta10" />
        <vers num="1.2.19" edition="beta11" />
        <vers num="1.2.19" edition="beta12" />
        <vers num="1.2.19" edition="beta13" />
        <vers num="1.2.19" edition="beta14" />
        <vers num="1.2.19" edition="beta15" />
        <vers num="1.2.19" edition="beta16" />
        <vers num="1.2.19" edition="beta17" />
        <vers num="1.2.19" edition="beta18" />
        <vers num="1.2.19" edition="beta19" />
        <vers num="1.2.19" edition="beta2" />
        <vers num="1.2.19" edition="beta20" />
        <vers num="1.2.19" edition="beta21" />
        <vers num="1.2.19" edition="beta22" />
        <vers num="1.2.19" edition="beta23" />
        <vers num="1.2.19" edition="beta24" />
        <vers num="1.2.19" edition="beta25" />
        <vers num="1.2.19" edition="beta26" />
        <vers num="1.2.19" edition="beta27" />
        <vers num="1.2.19" edition="beta28" />
        <vers num="1.2.19" edition="beta29" />
        <vers num="1.2.19" edition="beta3" />
        <vers num="1.2.19" edition="beta30" />
        <vers num="1.2.19" edition="beta31" />
        <vers num="1.2.19" edition="beta32" />
        <vers num="1.2.19" edition="beta33" />
        <vers num="1.2.19" edition="beta4" />
        <vers num="1.2.19" edition="beta5" />
        <vers num="1.2.19" edition="beta6" />
        <vers num="1.2.19" edition="beta7" />
        <vers num="1.2.19" edition="beta8" />
        <vers num="1.2.19" edition="beta9" />
        <vers num="1.2.19" edition="rc1" />
        <vers num="1.2.19" edition="rc2" />
        <vers num="1.2.19" edition="rc3" />
        <vers num="1.2.19" edition="rc4" />
        <vers num="1.2.19" edition="rc5" />
        <vers num="1.2.19" edition="rc6" />
        <vers num="1.2.2" edition="beta1" />
        <vers num="1.2.2" edition="beta2" />
        <vers num="1.2.2" edition="beta3" />
        <vers num="1.2.2" edition="beta4" />
        <vers num="1.2.2" edition="beta5" />
        <vers num="1.2.2" edition="beta6" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.20" edition="beta01" />
        <vers num="1.2.20" edition="beta02" />
        <vers num="1.2.20" edition="beta03" />
        <vers num="1.2.20" edition="beta04" />
        <vers num="1.2.20" edition="rc1" />
        <vers num="1.2.20" edition="rc2" />
        <vers num="1.2.20" edition="rc3" />
        <vers num="1.2.20" edition="rc4" />
        <vers num="1.2.20" edition="rc5" />
        <vers num="1.2.20" edition="rc6" />
        <vers num="1.2.21" edition="beta1" />
        <vers num="1.2.21" edition="beta2" />
        <vers num="1.2.21" edition="rc1" />
        <vers num="1.2.21" edition="rc2" />
        <vers num="1.2.21" edition="rc3" />
        <vers num="1.2.22" edition="beta1" />
        <vers num="1.2.22" edition="beta2" />
        <vers num="1.2.22" edition="beta2-1.2.21" />
        <vers num="1.2.22" edition="beta3" />
        <vers num="1.2.22" edition="beta3-1.2.21" />
        <vers num="1.2.22" edition="beta4" />
        <vers num="1.2.22" edition="beta4-1.2.21" />
        <vers num="1.2.22" edition="rc1" />
        <vers num="1.2.22" edition="rc1-1.2.21" />
        <vers num="1.2.23" edition="beta01" />
        <vers num="1.2.23" edition="beta01-1.2.22" />
        <vers num="1.2.23" edition="beta02" />
        <vers num="1.2.23" edition="beta02-1.2.22" />
        <vers num="1.2.23" edition="beta03" />
        <vers num="1.2.23" edition="beta03-1.2.22" />
        <vers num="1.2.23" edition="beta04" />
        <vers num="1.2.23" edition="beta04-1.2.22" />
        <vers num="1.2.23" edition="beta05" />
        <vers num="1.2.23" edition="beta05-1.2.22" />
        <vers num="1.2.23" edition="rc01" />
        <vers num="1.2.23" edition="rc01-1.2.22" />
        <vers num="1.2.24" edition="beta01" />
        <vers num="1.2.24" edition="beta01-1.2.23" />
        <vers num="1.2.24" edition="beta02" />
        <vers num="1.2.24" edition="beta02-1.2.23" />
        <vers num="1.2.24" edition="beta03" />
        <vers num="1.2.24" edition="beta03-1.2.23" />
        <vers num="1.2.24" edition="rc01" />
        <vers num="1.2.24" edition="rc01-1.2.23" />
        <vers num="1.2.25" edition="beta01" />
        <vers num="1.2.25" edition="beta02" />
        <vers num="1.2.25" edition="beta03" />
        <vers num="1.2.25" edition="beta04" />
        <vers num="1.2.25" edition="beta05" />
        <vers num="1.2.25" edition="beta06" />
        <vers num="1.2.25" edition="rc01" />
        <vers num="1.2.25" edition="rc02" />
        <vers num="1.2.26" edition="beta01" />
        <vers num="1.2.26" edition="beta02" />
        <vers num="1.2.26" edition="beta03" />
        <vers num="1.2.26" edition="beta04" />
        <vers num="1.2.26" edition="beta05" />
        <vers num="1.2.26" edition="beta06" />
        <vers num="1.2.26" edition="rc01" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.3" edition="rc1" />
        <vers num="1.2.3" edition="rc2" />
        <vers num="1.2.3" edition="rc3" />
        <vers num="1.2.3" edition="rc4" />
        <vers num="1.2.3" edition="rc5" />
        <vers num="1.2.3" edition="rc6" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
        <vers num="1.2.32" />
        <vers num="1.2.33" />
        <vers num="1.2.34" />
        <vers num="1.2.35" />
        <vers num="1.2.36" />
        <vers num="1.2.37" edition="beta1" />
        <vers num="1.2.37" edition="beta2" />
        <vers num="1.2.37" edition="beta3" />
        <vers num="1.2.37" edition="rc1" />
        <vers num="1.2.38" edition="beta1" />
        <vers num="1.2.38" edition="rc1" />
        <vers num="1.2.38" edition="rc2" />
        <vers num="1.2.38" edition="rc3" />
        <vers num="1.2.39" edition="beta1" />
        <vers num="1.2.39" edition="beta2" />
        <vers num="1.2.39" edition="beta3" />
        <vers num="1.2.39" edition="beta4" />
        <vers num="1.2.39" edition="beta5" />
        <vers num="1.2.39" edition="rc1" />
        <vers num="1.2.4" edition="beta1" />
        <vers num="1.2.4" edition="beta2" />
        <vers num="1.2.4" edition="beta3" />
        <vers num="1.2.4" edition="rc1" />
        <vers num="1.2.40" edition="beta1" />
        <vers num="1.2.40" edition="rc1" />
        <vers num="1.2.41" edition="beta1" />
        <vers num="1.2.41" edition="beta11" />
        <vers num="1.2.41" edition="beta12" />
        <vers num="1.2.41" edition="beta13" />
        <vers num="1.2.41" edition="beta14" />
        <vers num="1.2.41" edition="beta16" />
        <vers num="1.2.41" edition="beta17" />
        <vers num="1.2.41" edition="beta18" />
        <vers num="1.2.41" edition="beta2" />
        <vers num="1.2.41" edition="beta3" />
        <vers num="1.2.41" edition="beta4" />
        <vers num="1.2.41" edition="beta5" />
        <vers num="1.2.41" edition="beta6" />
        <vers num="1.2.41" edition="beta7" />
        <vers num="1.2.41" edition="beta8" />
        <vers num="1.2.41" edition="beta9" />
        <vers num="1.2.41" edition="rc1" />
        <vers num="1.2.41" edition="rc2" />
        <vers num="1.2.41" edition="rc3" />
        <vers num="1.2.42" edition="beta1" />
        <vers num="1.2.42" edition="beta2" />
        <vers num="1.2.42" edition="rc1" />
        <vers num="1.2.42" edition="rc2" />
        <vers num="1.2.42" edition="rc3" />
        <vers num="1.2.42" edition="rc4" />
        <vers num="1.2.42" edition="rc5" />
        <vers num="1.2.5" edition="beta1" />
        <vers num="1.2.5" edition="beta2" />
        <vers num="1.2.5" edition="beta3" />
        <vers num="1.2.5" edition="rc1" />
        <vers num="1.2.5" edition="rc2" />
        <vers num="1.2.5" edition="rc3" />
        <vers num="1.2.6" edition="beta1" />
        <vers num="1.2.6" edition="beta2" />
        <vers num="1.2.6" edition="beta3" />
        <vers num="1.2.6" edition="beta4" />
        <vers num="1.2.6" edition="rc1" />
        <vers num="1.2.6" edition="rc2" />
        <vers num="1.2.6" edition="rc3" />
        <vers num="1.2.6" edition="rc4" />
        <vers num="1.2.6" edition="rc5" />
        <vers num="1.2.7" edition="beta1" />
        <vers num="1.2.7" edition="beta2" />
        <vers num="1.2.8" edition="beta1" />
        <vers num="1.2.8" edition="beta2" />
        <vers num="1.2.8" edition="beta3" />
        <vers num="1.2.8" edition="beta4" />
        <vers num="1.2.8" edition="beta5" />
        <vers num="1.2.8" edition="rc1" />
        <vers num="1.2.8" edition="rc2" />
        <vers num="1.2.8" edition="rc3" />
        <vers num="1.2.8" edition="rc4" />
        <vers num="1.2.8" edition="rc5" />
        <vers num="1.2.9" edition="beta1" />
        <vers num="1.2.9" edition="beta10" />
        <vers num="1.2.9" edition="beta2" />
        <vers num="1.2.9" edition="beta3" />
        <vers num="1.2.9" edition="beta4" />
        <vers num="1.2.9" edition="beta5" />
        <vers num="1.2.9" edition="beta6" />
        <vers num="1.2.9" edition="beta7" />
        <vers num="1.2.9" edition="beta8" />
        <vers num="1.2.9" edition="beta9" />
        <vers num="1.2.9" edition="rc1" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta10" />
        <vers num="1.4" edition="beta11" />
        <vers num="1.4" edition="beta12" />
        <vers num="1.4" edition="beta13" />
        <vers num="1.4" edition="beta133" />
        <vers num="1.4" edition="beta14" />
        <vers num="1.4" edition="beta15" />
        <vers num="1.4" edition="beta16" />
        <vers num="1.4" edition="beta17" />
        <vers num="1.4" edition="beta18" />
        <vers num="1.4" edition="beta19" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4" edition="beta20" />
        <vers num="1.4" edition="beta22" />
        <vers num="1.4" edition="beta23" />
        <vers num="1.4" edition="beta24" />
        <vers num="1.4" edition="beta25" />
        <vers num="1.4" edition="beta26" />
        <vers num="1.4" edition="beta27" />
        <vers num="1.4" edition="beta28" />
        <vers num="1.4" edition="beta29" />
        <vers num="1.4" edition="beta3" />
        <vers num="1.4" edition="beta30" />
        <vers num="1.4" edition="beta31" />
        <vers num="1.4" edition="beta33" />
        <vers num="1.4" edition="beta4" />
        <vers num="1.4" edition="beta5" />
        <vers num="1.4" edition="beta6" />
        <vers num="1.4" edition="beta7" />
        <vers num="1.4" edition="beta8" />
        <vers num="1.4" edition="beta9" />
        <vers num="1.4.0" edition="beta36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0209" published="2010-08-11" name="CVE-2010-0209" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0192" source="VUPEN">ADV-2011-0192</ref>
      <ref url="http://www.securitytracker.com/id?1024621" source="SECTRACK">1024621</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-16.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-16.html</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-09.xml" source="GENTOO">GLSA-201101-09</ref>
      <ref url="http://secunia.com/advisories/43026" source="SECUNIA">43026</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11461" source="OVAL">oval:org.mitre.oval:def:11461</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=128767780602751&amp;w=2" source="HP">HPSBMA02592</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=128767780602751&amp;w=2" source="HP">HPSBMA02592</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="adobe_air">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.3" />
        <vers num="1.5.3.9120" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers num="10.0.12.36" />
        <vers num="10.0.15.3" />
        <vers num="10.0.22.87" />
        <vers num="10.0.32.18" />
        <vers num="10.0.42.34" />
        <vers num="10.0.45.2" />
        <vers num="10.1.52.14.1" />
        <vers num="10.1.52.15" />
        <vers prev="1" num="10.1.53.64" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8" />
        <vers num="8.0.22.0" />
        <vers num="8.0.33.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="8.0.42.0" />
        <vers num="9" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.125.0" />
        <vers num="9.0.151.0" />
        <vers num="9.0.152.0" />
        <vers num="9.0.159.0" />
        <vers num="9.0.16" />
        <vers num="9.0.18d60" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.246.0" />
        <vers num="9.0.260.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="9.125.0" />
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers num="10.0.12.36" />
        <vers num="10.0.15.3" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.151.0" />
        <vers num="9.0.31" />
        <vers num="9.0.48.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0211" published="2010-07-28" name="CVE-2010-0211" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41770" source="BID" patch="1">41770</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0025" source="VUPEN">ADV-2011-0025</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1858" source="VUPEN" adv="1">ADV-2010-1858</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1849" source="VUPEN" adv="1">ADV-2010-1849</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0001.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0001.html</ref>
      <ref url="http://www.securitytracker.com/id?1024221" source="SECTRACK">1024221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515545/100/0/threaded" source="BUGTRAQ">20110105 VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0543.html" source="REDHAT">RHSA-2010:0543</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0542.html" source="REDHAT">RHSA-2010:0542</ref>
      <ref url="http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570" source="CONFIRM">http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/42787" source="SECUNIA">42787</ref>
      <ref url="http://secunia.com/advisories/40687" source="SECUNIA" adv="1">40687</ref>
      <ref url="http://secunia.com/advisories/40677" source="SECUNIA" adv="1">40677</ref>
      <ref url="http://secunia.com/advisories/40639" source="SECUNIA" adv="1">40639</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="2.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0212" published="2010-07-28" name="CVE-2010-0212" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is not properly handled by the smr_normalize function and triggers a NULL pointer dereference in the IA5StringNormalize function in schema_init.c, as demonstrated using the Codenomicon LDAPv3 test suite.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1849" source="VUPEN" patch="1" adv="1">ADV-2010-1849</ref>
      <ref url="http://www.securityfocus.com/bid/41770" source="BID" patch="1">41770</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0025" source="VUPEN">ADV-2011-0025</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1858" source="VUPEN" adv="1">ADV-2010-1858</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0001.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0001.html</ref>
      <ref url="http://www.securitytracker.com/id?1024221" source="SECTRACK">1024221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515545/100/0/threaded" source="BUGTRAQ">20110105 VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0542.html" source="REDHAT">RHSA-2010:0542</ref>
      <ref url="http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570" source="CONFIRM">http://www.openldap.org/its/index.cgi/Software%20Bugs?id=6570</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/42787" source="SECUNIA">42787</ref>
      <ref url="http://secunia.com/advisories/40687" source="SECUNIA" adv="1">40687</ref>
      <ref url="http://secunia.com/advisories/40639" source="SECUNIA" adv="1">40639</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openldap" name="openldap">
        <vers num="2.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0213" published="2010-07-28" name="CVE-2010-0213" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/211905" source="CERT-VN">VU#211905</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1884" source="VUPEN" adv="1">ADV-2010-1884</ref>
      <ref url="http://www.securitytracker.com/id?1024217" source="SECTRACK">1024217</ref>
      <ref url="http://www.securityfocus.com/bid/41730" source="BID">41730</ref>
      <ref url="http://www.isc.org/software/bind/advisories/cve-2010-0213" source="CONFIRM" adv="1">http://www.isc.org/software/bind/advisories/cve-2010-0213</ref>
      <ref url="http://secunia.com/advisories/40709" source="SECUNIA" adv="1">40709</ref>
      <ref url="http://secunia.com/advisories/40652" source="SECUNIA" adv="1">40652</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html" source="SUSE">SUSE-SR:2010:020</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044445.html" source="FEDORA">FEDORA-2010-11344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.7.1" />
        <vers num="9.7.1-p1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0214" published="2011-01-11" name="CVE-2010-0214" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The administrative interface on the PolyVision RoomWizard with firmware 3.2.3 places the Sync Connector Active Directory (AD) credentials in a web form that is accessed over HTTP on port 80, which allows remote attackers to obtain sensitive information by reading the HTML source code corresponding to the /admin/sign/DeviceSynch URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/870601" source="CERT-VN">VU#870601</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64543" source="XF">roomwizard-password-security-bypass(64543)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0059" source="VUPEN" adv="1">ADV-2011-0059</ref>
      <ref url="http://www.securityfocus.com/bid/45699" source="BID">45699</ref>
      <ref url="http://seclists.org/fulldisclosure/2011/Jan/58" source="FULLDISC">20110106 RoomWizard Default Password and Sync Connector Credential Leak [CVE-2010-0214]</ref>
      <ref url="http://packetstormsecurity.org/files/view/97291/roomwizard-disclose.txt" source="MISC">http://packetstormsecurity.org/files/view/97291/roomwizard-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="polyvision" name="roomwizard_firmware">
        <vers num="3.2.3" />
      </prod>
      <prod vendor="polyvision" name="roomwizard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0215" published="2011-01-07" name="CVE-2010-0215" modified="2011-01-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/236703" source="CERT-VN">VU#236703</ref>
      <ref url="http://www.activecollab.com/docs/manuals/admin/release-notes/activecollab-2-3-2" source="CONFIRM">http://www.activecollab.com/docs/manuals/admin/release-notes/activecollab-2-3-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="a51dev" name="activecollab">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3" />
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0216" published="2011-05-10" name="CVE-2010-0216" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requests that use the UserID parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/67082" source="XF">mediacast-authenticateadsetup-info-disc(67082)</ref>
      <ref url="http://www.securityfocus.com/bid/47572" source="BID">47572</ref>
      <ref url="http://www.packetninjas.net/storage/advisories/MediaCast-PWDump-FINAL.txt" source="MISC">http://www.packetninjas.net/storage/advisories/MediaCast-PWDump-FINAL.txt</ref>
      <ref url="http://www.osvdb.org/72079" source="OSVDB">72079</ref>
      <ref url="http://securityreason.com/securityalert/8245" source="SREASON">8245</ref>
      <ref url="http://secunia.com/advisories/44182" source="SECUNIA" adv="1">44182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inventivetec" name="mediacast">
        <vers prev="1" num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0217" published="2011-05-20" name="CVE-2010-0217" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions or cause a denial of service (Chat Server crash or Tomcat daemon crash) via a brute-force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/67540" source="XF">chat-server-jsessionid-session-hijacking(67540)</ref>
      <ref url="http://www.securityfocus.com/bid/47910" source="BID">47910</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/518037/100/0/threaded" source="BUGTRAQ">20110517 CVE-2010-0217 - Zeacom Chat Server JSESSIONID weak SessionID Vulnerability</ref>
      <ref url="http://www.packetninjas.net/storage/advisories/Zeacom-CVE-2010-0217.txt" source="MISC">http://www.packetninjas.net/storage/advisories/Zeacom-CVE-2010-0217.txt</ref>
      <ref url="http://securityreason.com/securityalert/8255" source="SREASON">8255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeacom" name="chat_server">
        <vers prev="1" num="5.0" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0218" published="2010-10-05" name="CVE-2010-0218" modified="2010-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potentially sensitive information via a DNS query.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/784855" source="CERT-VN">VU#784855</ref>
      <ref url="http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.html" source="CONFIRM" patch="1">http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.html</ref>
      <ref url="https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html" source="MLIST" adv="1">[bind-announce] 20100928 Security Advisory Regarding Unexpected ACL Behavior in BIND 9.7.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.7.2" />
        <vers num="9.7.2-p1" />
        <vers num="9.7.2b1" />
        <vers num="9.7.2rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0219" published="2010-10-18" name="CVE-2010-0219" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/989719" source="CERT-VN">VU#989719</ref>
      <ref url="https://service.sap.com/sap/support/notes/1432881" source="MISC" patch="1">https://service.sap.com/sap/support/notes/1432881</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/62523" source="XF">businessobjects-dswsbobje-security-bypass(62523)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2673" source="VUPEN" adv="1">ADV-2010-2673</ref>
      <ref url="http://www.securitytracker.com/id?1024929" source="SECTRACK">1024929</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514284/100/0/threaded" source="BUGTRAQ">20101014 R7-0037: SAP BusinessObjects Axis2 Default Admin Password</ref>
      <ref url="http://www.rapid7.com/security-center/advisories/R7-0037.jsp" source="MISC">http://www.rapid7.com/security-center/advisories/R7-0037.jsp</ref>
      <ref url="http://www.osvdb.org/70233" source="OSVDB">70233</ref>
      <ref url="http://www.exploit-db.com/exploits/15869" source="EXPLOIT-DB">15869</ref>
      <ref url="http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf" source="MISC">http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf</ref>
      <ref url="http://secunia.com/advisories/42763" source="SECUNIA">42763</ref>
      <ref url="http://secunia.com/advisories/41799" source="SECUNIA" adv="1">41799</ref>
      <ref url="http://retrogod.altervista.org/9sg_ca_d2d.html" source="MISC">http://retrogod.altervista.org/9sg_ca_d2d.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="axis2">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.6" />
      </prod>
      <prod vendor="sap" name="businessobjects">
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":enterprise_xi" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0220" published="2010-01-07" name="CVE-2010-0220" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/" source="CONFIRM" patch="1">http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=7897" source="MISC" patch="1">http://isc.sans.org/diary.html?storyid=7897</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=507114" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=507114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55550" source="XF">firefox-nsobserverlist-dos(55550)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:000" source="MANDRIVA">MDVSA-2010:000</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8292" source="OVAL">oval:org.mitre.oval:def:8292</ref>
      <ref url="http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20" source="CONFIRM">http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.5" />
        <vers num="3.5" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers prev="1" num="3.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0221" published="2010-01-07" name="CVE-2010-0221" modified="2011-07-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55477" source="XF">kingston-access-control-sec-bypass(55477)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0080" source="VUPEN" adv="1">ADV-2010-0080</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf</ref>
      <ref url="http://www.kingston.com/driveupdate/" source="MISC">http://www.kingston.com/driveupdate/</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://securitytracker.com/id?1023410" source="SECTRACK">1023410</ref>
      <ref url="http://news.zdnet.co.uk/security/0,1000000189,39963327,00.htm" source="MISC">http://news.zdnet.co.uk/security/0,1000000189,39963327,00.htm</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingston" name="datatraveler_blackbox">
        <vers num="" />
      </prod>
      <prod vendor="kingston" name="datatraveler_elite">
        <vers num="" edition=":privacy" />
      </prod>
      <prod vendor="kingston" name="datatraveler_secure">
        <vers num="" edition=":privacy" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0222" published="2010-01-07" name="CVE-2010-0222" modified="2011-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0080" source="VUPEN">ADV-2010-0080</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf</ref>
      <ref url="http://www.kingston.com/driveupdate/" source="MISC" adv="1">http://www.kingston.com/driveupdate/</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://news.zdnet.co.uk/security/0,1000000189,39963327,00.htm" source="MISC">http://news.zdnet.co.uk/security/0,1000000189,39963327,00.htm</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingston" name="datatraveler_blackbox">
        <vers num="" />
      </prod>
      <prod vendor="kingston" name="datatraveler_elite">
        <vers num="" edition=":privacy" />
      </prod>
      <prod vendor="kingston" name="datatraveler_secure">
        <vers num="" edition=":privacy" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0223" published="2010-01-07" name="CVE-2010-0223" modified="2011-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0080" source="VUPEN">ADV-2010-0080</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf</ref>
      <ref url="http://www.kingston.com/driveupdate/" source="MISC" adv="1">http://www.kingston.com/driveupdate/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingston" name="datatraveler_blackbox">
        <vers num="" />
      </prod>
      <prod vendor="kingston" name="datatraveler_elite">
        <vers num="" edition=":privacy" />
      </prod>
      <prod vendor="kingston" name="datatraveler_secure">
        <vers num="" edition=":privacy" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0224" published="2010-01-07" name="CVE-2010-0224" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55475" source="XF">sandisk-access-control-sec-bypass(55475)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0078" source="VUPEN">ADV-2010-0078</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/37677" source="BID">37677</ref>
      <ref url="http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009" source="MISC" adv="1">http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://securitytracker.com/id?1023408" source="SECTRACK">1023408</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sandisk" name="cruzer_enterprise_usb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0225" published="2010-01-07" name="CVE-2010-0225" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0078" source="VUPEN">ADV-2010-0078</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/37677" source="BID">37677</ref>
      <ref url="http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009" source="MISC" adv="1">http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scandisk" name="cruzer_enterprise_usb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0226" published="2010-01-07" name="CVE-2010-0226" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0078" source="VUPEN">ADV-2010-0078</ref>
      <ref url="http://www.syss.de/index.php?id=108&amp;tx_ttnews%5Btt_news%5D=528&amp;cHash=8d16fa63d9" source="MISC">http://www.syss.de/index.php?id=108&amp;tx_ttnews[tt_news]=528&amp;cHash=8d16fa63d9</ref>
      <ref url="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf" source="MISC">http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/37677" source="BID">37677</ref>
      <ref url="http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009" source="MISC" adv="1">http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sandisk" name="cruzer_enterprise_usb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0227" published="2010-01-07" name="CVE-2010-0227" modified="2010-01-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.verbatim.com/security/security-update.cfm" source="MISC" adv="1">http://www.verbatim.com/security/security-update.cfm</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://securitytracker.com/id?1023409" source="SECTRACK">1023409</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verbatim" name="corporate_secure">
        <vers num="" edition=":" />
        <vers num="" edition="::fips" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0228" published="2010-01-07" name="CVE-2010-0228" modified="2010-01-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.verbatim.com/security/security-update.cfm" source="MISC" adv="1">http://www.verbatim.com/security/security-update.cfm</ref>
      <ref url="http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html" source="MISC">http://www.h-online.com/security/news/item/NIST-certified-USB-Flash-drives-with-hardware-encryption-cracked-895308.html</ref>
      <ref url="http://it.slashdot.org/story/10/01/05/1734242/" source="MISC">http://it.slashdot.org/story/10/01/05/1734242/</ref>
      <ref url="http://blogs.zdnet.com/hardware/?p=6655" source="MISC">http://blogs.zdnet.com/hardware/?p=6655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verbatim" name="corporate_secure">
        <vers num="" edition=":fips" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0229" published="2010-01-07" name="CVE-2010-0229" modified="2010-01-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.ironkey.com/usb-flash-drive-flaw-exposed" source="MISC">https://www.ironkey.com/usb-flash-drive-flaw-exposed</ref>
      <ref url="http://www.verbatim.com/security/security-update.cfm" source="MISC" adv="1">http://www.verbatim.com/security/security-update.cfm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="verbatim" name="corporate_secure">
        <vers num="" edition=":fips" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0230" published="2010-01-22" name="CVE-2010-0230" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00004.html" source="SUSE">SUSE-SA:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html" source="SUSE" adv="1">SUSE-SR:2010:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="opensuse">
        <vers num="11.2" />
      </prod>
      <prod vendor="suse" name="suse_linux">
        <vers num="10" edition="sp3" />
        <vers num="10" edition="sp3:enterprise_desktop" />
        <vers num="10" edition="sp3:enterprise_server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0231" published="2010-02-10" name="CVE-2010-0231" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx" source="MS" patch="1" adv="1">MS10-012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7751" source="OVAL">oval:org.mitre.oval:def:7751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0232" published="2010-01-21" name="CVE-2010-0232" modified="2011-05-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx" source="MS" patch="1" adv="1">MS10-015</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/979682.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/979682.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55742" source="XF">ms-win-gptrap-privilege-escalation(55742)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0179" source="VUPEN" adv="1">ADV-2010-0179</ref>
      <ref url="http://www.securityfocus.com/bid/37864" source="BID">37864</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509106/100/0/threaded" source="BUGTRAQ">20100119 Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack</ref>
      <ref url="http://securitytracker.com/id?1023471" source="SECTRACK">1023471</ref>
      <ref url="http://secunia.com/advisories/38265" source="SECUNIA" adv="1">38265</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Jan/341" source="FULLDISC">20100119 Microsoft Windows NT #GP Trap Handler Allows Users to Switch Kernel Stack</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8344" source="OVAL">oval:org.mitre.oval:def:8344</ref>
      <ref url="http://lock.cmpxchg8b.com/c0af0967d904cef2ad4db766a00bc6af/KiTrap0D.zip" source="MISC">http://lock.cmpxchg8b.com/c0af0967d904cef2ad4db766a00bc6af/KiTrap0D.zip</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-January/006000.html" source="MLIST">[dailydave] 20100119 We hold these axioms to be self evident</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows-nt">
        <vers num="3.1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="sp1" />
        <vers num="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="sp2" />
        <vers num="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0233" published="2010-02-10" name="CVE-2010-0233" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/slices/2000.html#d

"CWE-415 Double Free" vulnerability</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx" source="MS" adv="1">MS10-015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8392" source="OVAL">oval:org.mitre.oval:def:8392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="sp1" />
        <vers num="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="sp2" />
        <vers num="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0234" published="2010-04-14" name="CVE-2010-0234" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39374" source="SECUNIA">39374</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6814" source="OVAL">oval:org.mitre.oval:def:6814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0235" published="2010-04-14" name="CVE-2010-0235" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7509" source="OVAL">oval:org.mitre.oval:def:7509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0236" published="2010-04-14" name="CVE-2010-0236" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7113" source="OVAL">oval:org.mitre.oval:def:7113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0237" published="2010-04-14" name="CVE-2010-0237" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7130" source="OVAL">oval:org.mitre.oval:def:7130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0238" published="2010-04-14" name="CVE-2010-0238" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6793" source="OVAL">oval:org.mitre.oval:def:6793</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0239" published="2010-02-10" name="CVE-2010-0239" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx" source="MS" patch="1" adv="1">MS10-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8478" source="OVAL">oval:org.mitre.oval:def:8478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0240" published="2010-02-10" name="CVE-2010-0240" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx" source="MS" patch="1" adv="1">MS10-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8400" source="OVAL">oval:org.mitre.oval:def:8400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0241" published="2010-02-10" name="CVE-2010-0241" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx" source="MS" patch="1" adv="1">MS10-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8516" source="OVAL">oval:org.mitre.oval:def:8516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0242" published="2010-02-10" name="CVE-2010-0242" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx" source="MS" patch="1" adv="1">MS10-009</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8449" source="OVAL">oval:org.mitre.oval:def:8449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0243" published="2010-02-10" name="CVE-2010-0243" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-003.mspx" source="MS" adv="1">MS10-003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8399" source="OVAL">oval:org.mitre.oval:def:8399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0244" published="2010-01-22" name="CVE-2010-0244" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55774" source="XF">ie-deleted-obj-code-exec(55774)</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" adv="1">MS10-002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8186" source="OVAL">oval:org.mitre.oval:def:8186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="6.0" />
        <vers num="6.0.2600" />
        <vers num="6.0.2800" />
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900" />
        <vers num="6.0.2900.2180" />
        <vers num="6.00.2462.0000" />
        <vers num="6.00.2479.0006" />
        <vers num="6.00.2600.0000" />
        <vers num="6.00.2800.1106" />
        <vers num="6.00.2900.2180" />
        <vers num="6.00.3663.0000" />
        <vers num="6.00.3718.0000" />
        <vers num="6.00.3790.0000" />
        <vers num="6.00.3790.1830" />
        <vers num="6.00.3790.3959" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.5730" edition="unknown" />
        <vers num="7.0.5730" edition="unknown:gold" />
        <vers num="7.0.5730.11" />
        <vers num="7.00.5730.1100" />
        <vers num="7.00.6000.16386" />
        <vers num="7.00.6000.16441" />
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0245" published="2010-01-22" name="CVE-2010-0245" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" patch="1" adv="1">MS10-002</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55775" source="XF">ie-uninitialized-memory-code-exec(55775)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8491" source="OVAL">oval:org.mitre.oval:def:8491</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0246" published="2010-01-22" name="CVE-2010-0246" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55776" source="XF">ie-deleted-object-code-exec(55776)</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" adv="1">MS10-002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8378" source="OVAL">oval:org.mitre.oval:def:8378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0247" published="2010-01-22" name="CVE-2010-0247" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55777" source="XF">ie-uninitialized-obj-code-exec(55777)</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" adv="1">MS10-002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8506" source="OVAL">oval:org.mitre.oval:def:8506</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="6.0" />
        <vers num="6.0.2600" />
        <vers num="6.0.2800" />
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900" />
        <vers num="6.0.2900.2180" />
        <vers num="6.00.2462.0000" />
        <vers num="6.00.2479.0006" />
        <vers num="6.00.2600.0000" />
        <vers num="6.00.2800.1106" />
        <vers num="6.00.2900.2180" />
        <vers num="6.00.3663.0000" />
        <vers num="6.00.3718.0000" />
        <vers num="6.00.3790.0000" />
        <vers num="6.00.3790.1830" />
        <vers num="6.00.3790.3959" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0248" published="2010-01-22" name="CVE-2010-0248" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS" patch="1" adv="1">MS10-002</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55778" source="XF">ie-object-memory-code-exec(55778)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8267" source="OVAL">oval:org.mitre.oval:def:8267</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="6.0" />
        <vers num="6.0.2600" />
        <vers num="6.0.2800" />
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900" />
        <vers num="6.0.2900.2180" />
        <vers num="6.00.2462.0000" />
        <vers num="6.00.2479.0006" />
        <vers num="6.00.2600.0000" />
        <vers num="6.00.2800.1106" />
        <vers num="6.00.2900.2180" />
        <vers num="6.00.3663.0000" />
        <vers num="6.00.3718.0000" />
        <vers num="6.00.3790.0000" />
        <vers num="6.00.3790.1830" />
        <vers num="6.00.3790.3959" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="7.0.5730" edition="unknown" />
        <vers num="7.0.5730" edition="unknown:gold" />
        <vers num="7.0.5730.11" />
        <vers num="7.00.5730.1100" />
        <vers num="7.00.6000.16386" />
        <vers num="7.00.6000.16441" />
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0249" published="2010-01-15" name="CVE-2010-0249" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/416.htmlhttp://cwe.mitre.org/data/definitions/416.html

CWE-416: Use After Free</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-055A.html" source="CERT">TA10-055A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/492515" source="CERT-VN">VU#492515</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55642" source="XF">ie-freed-object-code-execution(55642)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0135" source="VUPEN">ADV-2010-0135</ref>
      <ref url="http://www.securityfocus.com/bid/37815" source="BID">37815</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx" source="MS">MS10-002</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/979352.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/979352.mspx</ref>
      <ref url="http://www.exploit-db.com/exploits/11167" source="EXPLOIT-DB">11167</ref>
      <ref url="http://support.microsoft.com/kb/979352" source="MSKB" adv="1">979352</ref>
      <ref url="http://securitytracker.com/id?1023462" source="SECTRACK">1023462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6835" source="OVAL">oval:org.mitre.oval:def:6835</ref>
      <ref url="http://osvdb.org/61697" source="OSVDB">61697</ref>
      <ref url="http://news.cnet.com/8301-27080_3-10435232-245.html" source="MISC">http://news.cnet.com/8301-27080_3-10435232-245.html</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0250" published="2010-02-10" name="CVE-2010-0250" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-015/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-015/</ref>
      <ref url="http://www.securityfocus.com/bid/38112" source="BID">38112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509472/100/0/threaded" source="BUGTRAQ">20100209 ZDI-10-015: Microsoft Windows RLE Video Decompressor Remote Code Execution Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx" source="MS" adv="1">MS10-013</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100074167" source="CONFIRM">http://support.avaya.com/css/P8/documents/100074167</ref>
      <ref url="http://secunia.com/advisories/38511" source="SECUNIA" adv="1">38511</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8064" source="OVAL">oval:org.mitre.oval:def:8064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0252" published="2010-02-10" name="CVE-2010-0252" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-040A.html" source="CERT">TA10-040A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx" source="MS" patch="1" adv="1">MS10-008</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx" source="MS">MS10-034</ref>
      <ref url="http://secunia.com/advisories/40059" source="SECUNIA">40059</ref>
      <ref url="http://secunia.com/advisories/38503" source="SECUNIA" adv="1">38503</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8424" source="OVAL">oval:org.mitre.oval:def:8424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0254" published="2010-04-14" name="CVE-2010-0254" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-028.mspx

'Users of Microsoft Office Visio 2002 and later versions of Visio will be prompted with Open, Save, or Cancel before opening a document. This is a mitigating factor because the vulnerability requires more than a single user action to complete the exploit.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-028.mspx" source="MS" patch="1" adv="1">MS10-028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6819" source="OVAL">oval:org.mitre.oval:def:6819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0255" published="2010-02-04" name="CVE-2010-0255" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.securityfocus.com/bid/38056" source="BID">38056</ref>
      <ref url="http://www.securityfocus.com/bid/38055" source="BID">38055</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509345/100/0/threaded" source="BUGTRAQ">20100203 CORE-2009-0625: Internet Explorer Dynamic OBJECT tag and URLMON sniffing vulnerabilities</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS">MS10-035</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/980088.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/980088.mspx</ref>
      <ref url="http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag" source="MISC">http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7145" source="OVAL">oval:org.mitre.oval:def:7145</ref>
      <ref url="http://osvdb.org/62156" source="OSVDB">62156</ref>
      <ref url="http://isc.sans.org/diary.html?n&amp;storyid=8152" source="MISC">http://isc.sans.org/diary.html?n&amp;storyid=8152</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/02/03/security-advisory-980088-released.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2010/02/03/security-advisory-980088-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0256" published="2010-04-14" name="CVE-2010-0256" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-028.mspx

'Users of Microsoft Office Visio 2002 and later versions of Visio will be prompted with Open, Save, or Cancel before opening a document. This is a mitigating factor because the vulnerability requires more than a single user action to complete the exploit.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-028.mspx" source="MS" patch="1" adv="1">MS10-028</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6732" source="OVAL">oval:org.mitre.oval:def:6732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0257" published="2010-03-10" name="CVE-2010-0257" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8617" source="OVAL">oval:org.mitre.oval:def:8617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0258" published="2010-03-10" name="CVE-2010-0258" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8545" source="OVAL">oval:org.mitre.oval:def:8545</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=859" source="IDEFENSE">20100309 Microsoft Excel Sheet Object Type Confusion Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0260" published="2010-03-10" name="CVE-2010-0260" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7862" source="OVAL">oval:org.mitre.oval:def:7862</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=862" source="IDEFENSE">20100309 Microsoft Excel MDXTUPLE Record Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0261" published="2010-03-10" name="CVE-2010-0261" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8479" source="OVAL">oval:org.mitre.oval:def:8479</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=861" source="IDEFENSE">20100309 Microsoft Excel MDXSET Record Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0262" published="2010-03-10" name="CVE-2010-0262" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8562" source="OVAL">oval:org.mitre.oval:def:8562</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=860" source="IDEFENSE">20100309 Microsoft Excel FNGROUPNAME Record Uninitialized Memory Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0263" published="2010-03-10" name="CVE-2010-0263" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, which allows remote attackers to execute arbitrary code via a crafted document that triggers access to uninitialized memory locations, aka "Microsoft Office Excel XLSX File Parsing Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-025/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-025/</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509979/100/0/threaded" source="BUGTRAQ">20100309 ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8407" source="OVAL">oval:org.mitre.oval:def:8407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0264" published="2010-03-10" name="CVE-2010-0264" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx" source="MS" patch="1" adv="1">MS10-017</ref>
      <ref url="http://www.securitytracker.com/id?1023698" source="SECTRACK">1023698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7888" source="OVAL">oval:org.mitre.oval:def:7888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0265" published="2010-03-10" name="CVE-2010-0265" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-016.mspx



'[1]These versions of Windows Movie Maker are delivered with the indicated operating systems.

[2]Windows Movie Maker 2.6 is an optional download that can be installed on the indicated operating systems. Windows 7 systems without Movie Maker 2.6 installed are not affected.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-016.mspx" source="MS" patch="1" adv="1">MS10-016</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8595" source="OVAL">oval:org.mitre.oval:def:8595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="producer">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="windows_movie_maker">
        <vers num="2.1" />
        <vers num="2.6" />
        <vers num="6.0" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0266" published="2010-07-15" name="CVE-2010-0266" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-194A.html" source="CERT">TA10-194A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-045.mspx" source="MS" patch="1" adv="1">MS10-045</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11623" source="OVAL">oval:org.mitre.oval:def:11623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0267" published="2010-03-31" name="CVE-2010-0267" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 5.01 Service Pack 4 and Internet Explorer 8 are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39023" source="BID" patch="1">39023</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8554" source="OVAL">oval:org.mitre.oval:def:8554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0268" published="2010-04-14" name="CVE-2010-0268" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-027.mspx" source="MS" patch="1" adv="1">MS10-027</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7281" source="OVAL">oval:org.mitre.oval:def:7281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0269" published="2010-04-14" name="CVE-2010-0269" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx" source="MS" patch="1" adv="1">MS10-020</ref>
      <ref url="http://secunia.com/advisories/39372" source="SECUNIA">39372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7129" source="OVAL">oval:org.mitre.oval:def:7129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0270" published="2010-04-14" name="CVE-2010-0270" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx" source="MS" patch="1" adv="1">MS10-020</ref>
      <ref url="http://secunia.com/advisories/39372" source="SECUNIA">39372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7164" source="OVAL">oval:org.mitre.oval:def:7164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0271" published="2010-01-08" name="CVE-2010-0271" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55461" source="XF">opensolaris-hald-weak-security(55461)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0076" source="VUPEN">ADV-2010-0076</ref>
      <ref url="http://www.securitytracker.com/id?1023416" source="SECTRACK">1023416</ref>
      <ref url="http://www.securityfocus.com/bid/37656" source="BID">37656</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-274830-1" source="SUNALERT" adv="1">274830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":x86" />
        <vers num="snv_111" edition=":sparc" />
        <vers num="snv_112" edition="" />
        <vers num="snv_112" edition=":x86" />
        <vers num="snv_112" edition=":sparc" />
        <vers num="snv_113" edition="" />
        <vers num="snv_113" edition=":sparc" />
        <vers num="snv_113" edition=":x86" />
        <vers num="snv_114" edition="" />
        <vers num="snv_114" edition=":x86" />
        <vers num="snv_114" edition=":sparc" />
        <vers num="snv_115" edition="" />
        <vers num="snv_115" edition=":sparc" />
        <vers num="snv_115" edition=":x86" />
        <vers num="snv_116" edition="" />
        <vers num="snv_116" edition=":sparc" />
        <vers num="snv_116" edition=":x86" />
        <vers num="snv_117" edition="" />
        <vers num="snv_117" edition=":x86" />
        <vers num="snv_117" edition=":sparc" />
        <vers num="snv_118" edition="" />
        <vers num="snv_118" edition=":x86" />
        <vers num="snv_118" edition=":sparc" />
        <vers num="snv_119" edition="" />
        <vers num="snv_119" edition=":x86" />
        <vers num="snv_119" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_120" edition="" />
        <vers num="snv_120" edition=":sparc" />
        <vers num="snv_120" edition=":x86" />
        <vers num="snv_121" edition="" />
        <vers num="snv_121" edition=":x86" />
        <vers num="snv_121" edition=":sparc" />
        <vers num="snv_122" edition="" />
        <vers num="snv_122" edition=":sparc" />
        <vers num="snv_122" edition=":x86" />
        <vers num="snv_123" edition="" />
        <vers num="snv_123" edition=":x86" />
        <vers num="snv_123" edition=":sparc" />
        <vers num="snv_124" edition="" />
        <vers num="snv_124" edition=":sparc" />
        <vers num="snv_124" edition=":x86" />
        <vers num="snv_125" edition="" />
        <vers num="snv_125" edition=":x86" />
        <vers num="snv_125" edition=":sparc" />
        <vers num="snv_126" edition="" />
        <vers num="snv_126" edition=":sparc" />
        <vers num="snv_126" edition=":x86" />
        <vers num="snv_127" edition="" />
        <vers num="snv_127" edition=":x86" />
        <vers num="snv_127" edition=":sparc" />
        <vers num="snv_128" edition="" />
        <vers num="snv_128" edition=":sparc" />
        <vers num="snv_128" edition=":x86" />
        <vers num="snv_129" edition="" />
        <vers num="snv_129" edition=":x86" />
        <vers num="snv_129" edition=":sparc" />
        <vers num="snv_130" edition="" />
        <vers num="snv_130" edition=":sparc" />
        <vers num="snv_130" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0272" published="2010-01-08" name="CVE-2010-0272" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco.  NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55527" source="XF">jsws-data-information-disclosure(55527)</ref>
      <ref url="http://www.intevydis.com/blog/?p=102" source="MISC">http://www.intevydis.com/blog/?p=102</ref>
      <ref url="http://intevydis.com/sjws_demo.html" source="MISC">http://intevydis.com/sjws_demo.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_6" />
        <vers num="7.0" edition="update_6:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0273" published="2010-01-08" name="CVE-2010-0273" modified="2010-01-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco.  NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.intevydis.com/blog/?p=102" source="MISC">http://www.intevydis.com/blog/?p=102</ref>
      <ref url="http://intevydis.com/sjws_demo.html" source="MISC">http://intevydis.com/sjws_demo.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_6" />
        <vers num="7.0" edition="update_6:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0274" published="2010-01-09" name="CVE-2010-0274" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.</descript>
    </desc>
    <sols>
      <sol source="nvd">http://www-933.ibm.com/support/fixcentral/</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55470" source="XF">domino-ultralight-unspecified(55470)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0077" source="VUPEN" adv="1">ADV-2010-0077</ref>
      <ref url="http://www.securityfocus.com/bid/37675" source="BID">37675</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27017776" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27017776</ref>
      <ref url="http://secunia.com/advisories/38026" source="SECUNIA" adv="1">38026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers prev="1" num="229.231" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0275" published="2010-01-09" name="CVE-2010-0275" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55471" source="XF">domino-script-command-unspecified(55471)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0077" source="VUPEN" adv="1">ADV-2010-0077</ref>
      <ref url="http://www.securityfocus.com/bid/37675" source="BID">37675</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27017776" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27017776</ref>
      <ref url="http://secunia.com/advisories/38026" source="SECUNIA" adv="1">38026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers prev="1" num="229.231" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0276" published="2010-01-09" name="CVE-2010-0276" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55473" source="XF">domino-trylotus-unspecified(55473)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0077" source="VUPEN" adv="1">ADV-2010-0077</ref>
      <ref url="http://www.securityfocus.com/bid/37675" source="BID">37675</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27017776" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27017776</ref>
      <ref url="http://secunia.com/advisories/38026" source="SECUNIA" adv="1">38026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="domino_web_access">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.0.2.3" />
      </prod>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0277" published="2010-01-09" name="CVE-2010-0277" modified="2010-11-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0115.html" source="REDHAT">RHSA-2010:0115</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=554335" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=554335</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2693" source="VUPEN" adv="1">ADV-2010-2693</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1020" source="VUPEN" adv="1">ADV-2010-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0413" source="VUPEN" adv="1">ADV-2010-0413</ref>
      <ref url="http://www.ubuntu.com/usn/USN-902-1" source="UBUNTU">USN-902-1</ref>
      <ref url="http://www.securityfocus.com/bid/38294" source="BID">38294</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/07/2" source="MLIST">[oss-security] 20100107 Re: CVE request - pidgin MSN arbitrary file upload</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:085" source="MANDRIVA">MDVSA-2010:085</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:041" source="MANDRIVA">MDVSA-2010:041</ref>
      <ref url="http://secunia.com/advisories/41868" source="SECUNIA" adv="1">41868</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA" adv="1">38915</ref>
      <ref url="http://secunia.com/advisories/38712" source="SECUNIA" adv="1">38712</ref>
      <ref url="http://secunia.com/advisories/38658" source="SECUNIA" adv="1">38658</ref>
      <ref url="http://secunia.com/advisories/38640" source="SECUNIA" adv="1">38640</ref>
      <ref url="http://secunia.com/advisories/38563" source="SECUNIA" adv="1">38563</ref>
      <ref url="http://pidgin.im/news/security/?id=43" source="CONFIRM">http://pidgin.im/news/security/?id=43</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9421" source="OVAL">oval:org.mitre.oval:def:9421</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.html" source="FEDORA">FEDORA-2010-1383</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.html" source="FEDORA">FEDORA-2010-1934</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.html" source="FEDORA">FEDORA-2010-1279</ref>
      <ref url="http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html" source="MISC">http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html</ref>
      <ref url="http://developer.pidgin.im/wiki/ChangeLog" source="CONFIRM">http://developer.pidgin.im/wiki/ChangeLog</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_0277_malformed_msn" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_0277_malformed_msn</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adium" name="adium">
        <vers num="1.3.8" />
      </prod>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0278" published="2010-01-12" name="CVE-2010-0278" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37680" source="BID">37680</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508811/100/0/threaded" source="BUGTRAQ">20100108 [HACKATTACK Advisory 080110] Windows Live Messenger 2009 ActiveX DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_live_messenger">
        <vers num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0279" published="2010-01-12" name="CVE-2010-0279" modified="2010-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.  NOTE: some of these details are obtained from third party information.</descript>
      <descript source="nvd">CWE-434 - http://cwe.mitre.org/data/definitions/434.html</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55462" source="XF">readexcel-upload-file-upload(55462)</ref>
      <ref url="http://www.exploit-db.com/exploits/11057" source="EXPLOIT-DB">11057</ref>
      <ref url="http://secunia.com/advisories/38083" source="SECUNIA" adv="1">38083</ref>
      <ref url="http://osvdb.org/61579" source="OSVDB">61579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bts-gi.net" name="read_excel">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0280" published="2010-01-15" name="CVE-2010-0280" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0133" source="VUPEN">ADV-2010-0133</ref>
      <ref url="http://www.securityfocus.com/bid/37708" source="BID">37708</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508913/100/0/threaded" source="BUGTRAQ">20100113 [CORE-2009-1209] Google SketchUp 'lib3ds' 3DS Importer Memory Corruption</ref>
      <ref url="http://www.coresecurity.com/content/google-sketchup-vulnerability" source="MISC">http://www.coresecurity.com/content/google-sketchup-vulnerability</ref>
      <ref url="http://sketchup.google.com/support/bin/answer.py?hl=en&amp;answer=141303" source="CONFIRM">http://sketchup.google.com/support/bin/answer.py?hl=en&amp;answer=141303</ref>
      <ref url="http://secunia.com/advisories/38187" source="SECUNIA" adv="1">38187</ref>
      <ref url="http://secunia.com/advisories/38185" source="SECUNIA" adv="1">38185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="google_sketchup">
        <vers num="7.0" />
        <vers num="7.0.10247" />
        <vers num="7.1.4871" />
        <vers num="7.1.6087" />
      </prod>
      <prod vendor="jan_eric_krprianidis" name="lib3ds">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0283" published="2010-02-22" name="CVE-2010-0283" modified="2010-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.ubuntu.com/usn/USN-916-1" source="UBUNTU">USN-916-1</ref>
      <ref url="http://www.securityfocus.com/bid/38260" source="BID">38260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509553/100/0/threaded" source="BUGTRAQ">20100216 MITKRB5-SA-2010-001 [CVE-2010-0283] krb5-1.7 KDC denial of service</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-001.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-001.txt</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1023593" source="SECTRACK">1023593</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/39023" source="SECUNIA">39023</ref>
      <ref url="http://secunia.com/advisories/38598" source="SECUNIA">38598</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035222.html" source="FEDORA">FEDORA-2010-1722</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0284" published="2010-06-18" name="CVE-2010-0284" modified="2010-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remote attackers to create arbitrary files with any contents, and consequently execute arbitrary code, via a .. (dot dot) in a parameter, aka ZDI-CAN-678.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59528" source="XF">accessmgr-admincosole-getentry-file-upload(59528)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1516" source="VUPEN" adv="1">ADV-2010-1516</ref>
      <ref url="http://www.securitytracker.com/id?1024132" source="SECTRACK">1024132</ref>
      <ref url="http://www.securityfocus.com/bid/40931" source="BID">40931</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7006255&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=7006255&amp;sliceId=1</ref>
      <ref url="http://secunia.com/advisories/40198" source="SECUNIA" adv="1">40198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="access_manager">
        <vers num="3.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0285" published="2010-02-24" name="CVE-2010-0285" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:N)" CVSS_score="5.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="1.9" CVSS_base_score="5.6">
    <desc>
      <descript source="cve">gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=557525" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=557525</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=593616" source="CONFIRM">https://bugzilla.gnome.org/show_bug.cgi?id=593616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56366" source="XF">screensaver-monitor-setup-sec-bypass(56366)</ref>
      <ref url="http://www.securityfocus.com/bid/38254" source="BID">38254</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:093" source="MANDRIVA">MDVSA-2011:093</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-0285" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-0285</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=2f597ea9f1f363277fd4dfc109fa41bbc6225aca" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=2f597ea9f1f363277fd4dfc109fa41bbc6225aca</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="screensaver">
        <vers num="2.14.3" />
        <vers num="2.22.2" />
        <vers num="2.27" />
        <vers num="2.28.0" />
        <vers num="2.28.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0286" published="2010-02-22" name="CVE-2010-0286" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0127" source="VUPEN" patch="1" adv="1">ADV-2010-0127</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55609" source="XF">typo3-openid-security-bypass(55609)</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-001/</ref>
      <ref url="http://secunia.com/advisories/38206" source="SECUNIA" adv="1">38206</ref>
      <ref url="http://osvdb.org/61680" source="OSVDB">61680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0287" published="2010-02-15" name="CVE-2010-0287" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55660" source="XF">dokuwiki-ajax-dir-traversal(55660)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0150" source="VUPEN">ADV-2010-0150</ref>
      <ref url="http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security" source="CONFIRM">http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security</ref>
      <ref url="http://www.securityfocus.com/bid/37821" source="BID">37821</ref>
      <ref url="http://www.exploit-db.com/exploits/11141" source="EXPLOIT-DB">11141</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1976" source="DEBIAN">DSA-1976</ref>
      <ref url="http://secunia.com/advisories/38183" source="SECUNIA" adv="1">38183</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034831.html" source="FEDORA">FEDORA-2010-0800</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034729.html" source="FEDORA">FEDORA-2010-0770</ref>
      <ref url="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847" source="CONFIRM">http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dokuwiki" name="dokuwiki">
        <vers num="release_2004-07-04" />
        <vers num="release_2004-07-07" />
        <vers num="release_2004-07-12" />
        <vers num="release_2004-07-21" />
        <vers num="release_2004-07-25" />
        <vers num="release_2004-08-08" />
        <vers num="release_2004-08-15a" />
        <vers num="release_2004-08-22" />
        <vers num="release_2004-09-12" />
        <vers num="release_2004-09-25" />
        <vers num="release_2004-09-30" />
        <vers num="release_2004-11-01" />
        <vers num="release_2004-11-02" />
        <vers num="release_2004-11-10" />
        <vers num="release_2005-01-14" />
        <vers num="release_2005-01-15" />
        <vers num="release_2005-01-16a" />
        <vers num="release_2005-02-06" />
        <vers num="release_2005-02-18" />
        <vers num="release_2005-05-07" />
        <vers num="release_2005-07-01" />
        <vers num="release_2005-07-13" />
        <vers num="release_2005-09-19" />
        <vers num="release_2005-09-22" />
        <vers num="release_2006-03-05" />
        <vers num="release_2006-03-09" />
        <vers num="release_2006-03-09e" />
        <vers num="release_2006-06-04" />
        <vers prev="1" num="release_2009-02-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0288" published="2010-02-15" name="CVE-2010-0288" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55661" source="XF">dokuwiki-ajax-security-bypass(55661)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0150" source="VUPEN">ADV-2010-0150</ref>
      <ref url="http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security" source="CONFIRM">http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security</ref>
      <ref url="http://www.securityfocus.com/bid/37820" source="BID">37820</ref>
      <ref url="http://www.exploit-db.com/exploits/11141" source="EXPLOIT-DB">11141</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1976" source="DEBIAN">DSA-1976</ref>
      <ref url="http://secunia.com/advisories/38183" source="SECUNIA" adv="1">38183</ref>
      <ref url="http://osvdb.org/61710" source="OSVDB">61710</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034831.html" source="FEDORA">FEDORA-2010-0800</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034729.html" source="FEDORA">FEDORA-2010-0770</ref>
      <ref url="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847" source="CONFIRM">http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dokuwiki" name="dokuwiki">
        <vers num="release_2004-07-04" />
        <vers num="release_2004-07-07" />
        <vers num="release_2004-07-12" />
        <vers num="release_2004-07-21" />
        <vers num="release_2004-07-25" />
        <vers num="release_2004-08-08" />
        <vers num="release_2004-08-15a" />
        <vers num="release_2004-08-22" />
        <vers num="release_2004-09-12" />
        <vers num="release_2004-09-25" />
        <vers num="release_2004-09-30" />
        <vers num="release_2004-11-01" />
        <vers num="release_2004-11-02" />
        <vers num="release_2004-11-10" />
        <vers num="release_2005-01-14" />
        <vers num="release_2005-01-15" />
        <vers num="release_2005-01-16a" />
        <vers num="release_2005-02-06" />
        <vers num="release_2005-02-18" />
        <vers num="release_2005-05-07" />
        <vers num="release_2005-07-01" />
        <vers num="release_2005-07-13" />
        <vers num="release_2005-09-19" />
        <vers num="release_2005-09-22" />
        <vers num="release_2006-03-05" />
        <vers num="release_2006-03-09" />
        <vers num="release_2006-03-09e" />
        <vers num="release_2006-06-04" />
        <vers prev="1" num="release_2009-02-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0289" published="2010-02-15" name="CVE-2010-0289" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security" source="CONFIRM">http://www.splitbrain.org/blog/2010-01/17-dokuwiki-security</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1976" source="DEBIAN">DSA-1976</ref>
      <ref url="http://secunia.com/advisories/38205" source="SECUNIA" adv="1">38205</ref>
      <ref url="http://osvdb.org/61708" source="OSVDB">61708</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034831.html" source="FEDORA">FEDORA-2010-0800</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034729.html" source="FEDORA">FEDORA-2010-0770</ref>
      <ref url="http://freshmeat.net/projects/dokuwiki/tags/security-fix" source="CONFIRM">http://freshmeat.net/projects/dokuwiki/tags/security-fix</ref>
      <ref url="http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1853" source="CONFIRM">http://bugs.splitbrain.org/index.php?do=details&amp;task_id=1853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dokuwiki" name="dokuwiki">
        <vers num="release_2004-07-04" />
        <vers num="release_2004-07-07" />
        <vers num="release_2004-07-12" />
        <vers num="release_2004-07-21" />
        <vers num="release_2004-07-25" />
        <vers num="release_2004-08-08" />
        <vers num="release_2004-08-15a" />
        <vers num="release_2004-08-22" />
        <vers num="release_2004-09-12" />
        <vers num="release_2004-09-25" />
        <vers num="release_2004-09-30" />
        <vers num="release_2004-11-01" />
        <vers num="release_2004-11-02" />
        <vers num="release_2004-11-10" />
        <vers num="release_2005-01-14" />
        <vers num="release_2005-01-15" />
        <vers num="release_2005-01-16a" />
        <vers num="release_2005-02-06" />
        <vers num="release_2005-02-18" />
        <vers num="release_2005-05-07" />
        <vers num="release_2005-07-01" />
        <vers num="release_2005-07-13" />
        <vers num="release_2005-09-19" />
        <vers num="release_2005-09-22" />
        <vers num="release_2006-03-05" />
        <vers num="release_2006-03-09" />
        <vers num="release_2006-03-09e" />
        <vers num="release_2006-06-04" />
        <vers prev="1" num="release_2009-02-14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0290" published="2010-01-22" name="CVE-2010-0290" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.isc.org/advisories/CVE-2009-4022v6" source="CONFIRM" adv="1">https://www.isc.org/advisories/CVE-2009-4022v6</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0062.html" source="REDHAT">RHSA-2010:0062</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=557121" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=557121</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=554851" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=554851</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1352" source="VUPEN">ADV-2010-1352</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0622" source="VUPEN">ADV-2010-0622</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0176" source="VUPEN" adv="1">ADV-2010-0176</ref>
      <ref url="http://www.ubuntu.com/usn/USN-888-1" source="UBUNTU">USN-888-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:021" source="MANDRIVA">MDVSA-2010:021</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2054" source="DEBIAN">DSA-2054</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018</ref>
      <ref url="http://secunia.com/advisories/40086" source="SECUNIA">40086</ref>
      <ref url="http://secunia.com/advisories/38240" source="SECUNIA" adv="1">38240</ref>
      <ref url="http://secunia.com/advisories/38219" source="SECUNIA" adv="1">38219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8884" source="OVAL">oval:org.mitre.oval:def:8884</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7512" source="OVAL">oval:org.mitre.oval:def:7512</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6815" source="OVAL">oval:org.mitre.oval:def:6815</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126399602810086&amp;w=2" source="MLIST">[oss-security] 20100120 Re: BIND CVE-2009-4022 fix incomplete</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126393609503704&amp;w=2" source="MLIST">[oss-security] 20100119 BIND CVE-2009-4022 fix incomplete</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00009.html" source="SUSE">SUSE-SA:2010:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.0" />
        <vers num="9.0.0" edition="rc1" />
        <vers num="9.0.0" edition="rc2" />
        <vers num="9.0.0" edition="rc3" />
        <vers num="9.0.0" edition="rc4" />
        <vers num="9.0.0" edition="rc5" />
        <vers num="9.0.0" edition="rc6" />
        <vers num="9.0.0b1" />
        <vers num="9.0.0b2" />
        <vers num="9.0.0b3" />
        <vers num="9.0.0b4" />
        <vers num="9.0.0b5" />
        <vers num="9.0.1" edition="rc1" />
        <vers num="9.0.1" edition="rc2" />
        <vers num="9.1" />
        <vers num="9.1.0" edition="rc1" />
        <vers num="9.1.0b1" />
        <vers num="9.1.0b2" />
        <vers num="9.1.0b3" />
        <vers num="9.1.1" edition="rc1" />
        <vers num="9.1.1" edition="rc2" />
        <vers num="9.1.1" edition="rc3" />
        <vers num="9.1.1" edition="rc4" />
        <vers num="9.1.1" edition="rc5" />
        <vers num="9.1.1" edition="rc6" />
        <vers num="9.1.1" edition="rc7" />
        <vers num="9.1.2" edition="rc1" />
        <vers num="9.1.3" edition="rc1" />
        <vers num="9.1.3" edition="rc2" />
        <vers num="9.1.3" edition="rc3" />
        <vers num="9.1.3p2" />
        <vers num="9.1.3p3" />
        <vers num="9.2.0" edition="rc1" />
        <vers num="9.2.0" edition="rc10" />
        <vers num="9.2.0" edition="rc2" />
        <vers num="9.2.0" edition="rc3" />
        <vers num="9.2.0" edition="rc4" />
        <vers num="9.2.0" edition="rc5" />
        <vers num="9.2.0" edition="rc6" />
        <vers num="9.2.0" edition="rc7" />
        <vers num="9.2.0" edition="rc8" />
        <vers num="9.2.0" edition="rc9" />
        <vers num="9.2.0a1" />
        <vers num="9.2.0a2" />
        <vers num="9.2.0a3" />
        <vers num="9.2.0b1" />
        <vers num="9.2.0b2" />
        <vers num="9.2.1" edition="rc1" />
        <vers num="9.2.1" edition="rc2" />
        <vers num="9.2.2" edition="p2" />
        <vers num="9.2.2" edition="p3" />
        <vers num="9.2.2" edition="rc1" />
        <vers num="9.2.3" edition="rc1" />
        <vers num="9.2.3" edition="rc2" />
        <vers num="9.2.3" edition="rc3" />
        <vers num="9.2.3" edition="rc4" />
        <vers num="9.2.4" edition="rc2" />
        <vers num="9.2.4" edition="rc3" />
        <vers num="9.2.4" edition="rc4" />
        <vers num="9.2.4" edition="rc5" />
        <vers num="9.2.4" edition="rc6" />
        <vers num="9.2.4" edition="rc7" />
        <vers num="9.2.4" edition="rc8" />
        <vers num="9.2.5" edition="beta2" />
        <vers num="9.2.5" edition="rc1" />
        <vers num="9.2.6" edition="rc1" />
        <vers num="9.2.6b1" />
        <vers num="9.2.6b2" />
        <vers num="9.2.6p1" />
        <vers num="9.2.6p2" />
        <vers num="9.2.7" edition="rc1" />
        <vers num="9.2.7" edition="rc2" />
        <vers num="9.2.7" edition="rc3" />
        <vers num="9.2.7b1" />
        <vers num="9.2.8" />
        <vers num="9.2.8p1" />
        <vers num="9.2.9" edition="rc1" />
        <vers num="9.2.9b1" />
        <vers num="9.3.0" edition="beta2" />
        <vers num="9.3.0" edition="beta3" />
        <vers num="9.3.0" edition="beta4" />
        <vers num="9.3.0" edition="rc1" />
        <vers num="9.3.0" edition="rc2" />
        <vers num="9.3.0" edition="rc3" />
        <vers num="9.3.0" edition="rc4" />
        <vers num="9.3.1" edition="beta2" />
        <vers num="9.3.1" edition="rc1" />
        <vers num="9.3.2" edition="rc1" />
        <vers num="9.3.2b1" />
        <vers num="9.3.2b2" />
        <vers num="9.3.2p1" />
        <vers num="9.3.2p2" />
        <vers num="9.3.3" edition="rc1" />
        <vers num="9.3.3" edition="rc2" />
        <vers num="9.3.3" edition="rc3" />
        <vers num="9.3.3b1" />
        <vers num="9.3.4" />
        <vers num="9.3.4p1" />
        <vers num="9.3.5" edition="rc1" />
        <vers num="9.3.5" edition="rc2" />
        <vers num="9.3.5-p2" />
        <vers num="9.3.5-p2-w1" />
        <vers num="9.3.5-p2-w2" />
        <vers num="9.3.5b1" />
        <vers num="9.3.6" edition="rc1" />
        <vers num="9.3.6b1" />
        <vers num="9.3.6p1" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0" edition="rc2" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.1p1" />
        <vers num="9.4.2" edition="rc1" />
        <vers num="9.4.2" edition="rc2" />
        <vers num="9.4.2b1" />
        <vers num="9.4.2p1" />
        <vers num="9.4.2p2" />
        <vers num="9.4.2p2-w1" />
        <vers num="9.4.2p2-w2" />
        <vers num="9.4.3p1" />
        <vers num="9.4.3p2" />
        <vers num="9.4.3p3" />
        <vers num="9.4.3p4" />
        <vers num="9.5" />
        <vers num="9.5.0" edition="rc1" />
        <vers num="9.5.0a5" />
        <vers num="9.5.0a6" />
        <vers num="9.5.0a7" />
        <vers num="9.5.0b1" />
        <vers num="9.5.0b2" />
        <vers num="9.5.0b3" />
        <vers num="9.5.1" edition="rc1" />
        <vers num="9.5.1" edition="rc2" />
        <vers num="9.5.1b1" />
        <vers num="9.5.1b2" />
        <vers num="9.5.1b3" />
        <vers num="9.5.1p1" />
        <vers num="9.5.1p2" />
        <vers num="9.5.1p3" />
        <vers num="9.5.2" edition="rc1" />
        <vers num="9.5.2b1" />
        <vers num="9.5.2p1" />
        <vers num="9.6.0" edition="p1" />
        <vers num="9.6.0" edition="rc1" />
        <vers num="9.6.0" edition="rc2" />
        <vers num="9.6.0a1" />
        <vers num="9.6.0b1" />
        <vers num="9.6.1" edition="p1" />
        <vers num="9.6.1" edition="p2" />
        <vers num="9.7.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0291" published="2010-02-15" name="CVE-2010-0291" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.4</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=556703" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=556703</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/37906" source="BID">37906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11824" source="OVAL">oval:org.mitre.oval:def:11824</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126406814304720&amp;w=2" source="MLIST">[oss-security] 20100121 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126400443123998&amp;w=2" source="MLIST">[oss-security] 20100120 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126399980216047&amp;w=2" source="MLIST">[oss-security] 20100120 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126396609004884&amp;w=2" source="MLIST">[oss-security] 20100120 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126396065732697&amp;w=2" source="MLIST">[oss-security] 20100120 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126395874130875&amp;w=2" source="MLIST">[oss-security] 20100120 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126393370931972&amp;w=2" source="MLIST">[oss-security] 20100119 Re: CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126388181420690&amp;w=2" source="MLIST">[oss-security] 20100119 CVE request - kernel: untangle the do_mremap() mess</ref>
      <ref url="http://marc.info/?l=linux-arch&amp;m=126004438008670&amp;w=2" source="MLIST">[linux-kernel] 20091205 [RFC][PATCHSET] mremap/mmap mess</ref>
      <ref url="http://groups.google.com/group/linux.kernel/msg/895f20870532241e" source="MLIST">[linux-kernel] 20100114 [PATCH 01/52] untangle the do_mremap() mess</ref>
      <ref url="http://groups.google.co.jp/group/fa.linux.kernel/browse_thread/thread/8bf22336b1082090" source="CONFIRM">http://groups.google.co.jp/group/fa.linux.kernel/browse_thread/thread/8bf22336b1082090</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f8b7256096a20436f6d0926747e3ac3d64c81d24" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f8b7256096a20436f6d0926747e3ac3d64c81d24</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f106af4e90eadd76cfc0b5325f659619e08fb762" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f106af4e90eadd76cfc0b5325f659619e08fb762</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ecc1a8993751de4e82eb18640d631dae1f626bd6" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ecc1a8993751de4e82eb18640d631dae1f626bd6</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e77414e0aad6a1b063ba5e5750c582c75327ea6a" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e77414e0aad6a1b063ba5e5750c582c75327ea6a</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c4caa778157dbbf04116f0ac2111e389b5cd7a29" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c4caa778157dbbf04116f0ac2111e389b5cd7a29</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bb52d6694002b9d632bb355f64daa045c6293a4e" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bb52d6694002b9d632bb355f64daa045c6293a4e</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=aa65607373a4daf2010e8c3867b6317619f3c1a3" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=aa65607373a4daf2010e8c3867b6317619f3c1a3</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=935874141df839c706cd6cdc438e85eb69d1525e" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=935874141df839c706cd6cdc438e85eb69d1525e</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9206de95b1ea68357996ec02be5db0638a0de2c1" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9206de95b1ea68357996ec02be5db0638a0de2c1</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8c7b49b3ecd48923eb64ff57e07a1cdb74782970" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=8c7b49b3ecd48923eb64ff57e07a1cdb74782970</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=570dcf2c15463842e384eb597a87c1e39bead99b" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=570dcf2c15463842e384eb597a87c1e39bead99b</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=564b3bffc619dcbdd160de597b0547a7017ea010" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=564b3bffc619dcbdd160de597b0547a7017ea010</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=54f5de709984bae0d31d823ff03de755f9dcac54" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=54f5de709984bae0d31d823ff03de755f9dcac54</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2ea1d13f64efdf49319e86c87d9ba38c30902782" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2ea1d13f64efdf49319e86c87d9ba38c30902782</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2c6a10161d0b5fc047b5bd81b03693b9af99fab5" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2c6a10161d0b5fc047b5bd81b03693b9af99fab5</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1a0ef85f84feb13f07b604fcf5b90ef7c2b5c82f" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1a0ef85f84feb13f07b604fcf5b90ef7c2b5c82f</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0ec62d290912bb4b989be7563851bc364ec73b56" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0ec62d290912bb4b989be7563851bc364ec73b56</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=097eed103862f9c6a97f2e415e21d1134017b135" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=097eed103862f9c6a97f2e415e21d1134017b135</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=05d72faa6d13c9d857478a5d35c85db9adada685" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=05d72faa6d13c9d857478a5d35c85db9adada685</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0067bd8a55862ac9dd212bd1c4f6f5bff1ca1301" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0067bd8a55862ac9dd212bd1c4f6f5bff1ca1301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="e1000">
        <vers num="5.2.22" />
        <vers num="5.2.30.1" />
        <vers num="5.2.52" />
        <vers num="5.3.19" />
        <vers num="5.4.11" />
        <vers num="5.5.4" />
        <vers num="5.6.10" />
        <vers num="5.6.10.1" />
        <vers num="5.7.6" />
        <vers num="6.0.54" />
        <vers num="6.0.60" />
        <vers num="6.1.16" />
        <vers num="6.2.15" />
        <vers num="6.3.9" />
        <vers num="7.0.33" />
        <vers num="7.0.41" />
        <vers num="7.1.9" />
        <vers num="7.2.7" />
        <vers num="7.2.9" />
        <vers num="7.3.15" />
        <vers num="7.3.20" />
        <vers num="7.4.27" />
        <vers prev="1" num="7.4.35" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers prev="1" num="2.6.32.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0292" published="2010-02-08" name="CVE-2010-0292" modified="2010-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to CVE-2009-3563.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38106" source="BID" patch="1">38106</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555367" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555367</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1992" source="DEBIAN">DSA-1992</ref>
      <ref url="http://secunia.com/advisories/38480" source="SECUNIA" adv="1">38480</ref>
      <ref url="http://secunia.com/advisories/38428" source="SECUNIA" adv="1">38428</ref>
      <ref url="http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=7864c7a70ce00369194e734eb2842ecc5f8db531" source="CONFIRM">http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=7864c7a70ce00369194e734eb2842ecc5f8db531</ref>
      <ref url="http://chrony.tuxfamily.org/News.html" source="CONFIRM" adv="1">http://chrony.tuxfamily.org/News.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tuxfamily" name="chrony">
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.19-1" />
        <vers num="1.19.99.1" />
        <vers num="1.19.99.2" />
        <vers num="1.19.99.3" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.21-pre1" />
        <vers prev="1" num="1.23-pre1" />
        <vers num="1.24-pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0293" published="2010-02-08" name="CVE-2010-0293" modified="2010-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555367" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555367</ref>
      <ref url="http://www.securityfocus.com/bid/38106" source="BID">38106</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1992" source="DEBIAN">DSA-1992</ref>
      <ref url="http://secunia.com/advisories/38480" source="SECUNIA" adv="1">38480</ref>
      <ref url="http://secunia.com/advisories/38428" source="SECUNIA" adv="1">38428</ref>
      <ref url="http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=2f63cf448560fdb96b80d8488aae6a15b802a753" source="CONFIRM">http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=2f63cf448560fdb96b80d8488aae6a15b802a753</ref>
      <ref url="http://chrony.tuxfamily.org/News.html" source="CONFIRM" adv="1">http://chrony.tuxfamily.org/News.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tuxfamily" name="chrony">
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.19-1" />
        <vers num="1.19.99.1" />
        <vers num="1.19.99.2" />
        <vers num="1.19.99.3" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.21-pre1" />
        <vers prev="1" num="1.23-pre1" />
        <vers num="1.24-pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0294" published="2010-02-08" name="CVE-2010-0294" modified="2010-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which allows remote attackers to cause a denial of service (disk consumption) via a large number of invalid packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38106" source="BID" patch="1">38106</ref>
      <ref url="http://chrony.tuxfamily.org/News.html" source="CONFIRM" patch="1" adv="1">http://chrony.tuxfamily.org/News.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555367" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555367</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1992" source="DEBIAN">DSA-1992</ref>
      <ref url="http://secunia.com/advisories/38480" source="SECUNIA" adv="1">38480</ref>
      <ref url="http://secunia.com/advisories/38428" source="SECUNIA" adv="1">38428</ref>
      <ref url="http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=0b710499f994823bd938fc6895f097eefb9cc59f" source="CONFIRM">http://git.tuxfamily.org/chrony/chrony.git/?p=gitroot/chrony/chrony.git;a=commit;h=0b710499f994823bd938fc6895f097eefb9cc59f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tuxfamily" name="chrony">
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.19-1" />
        <vers num="1.19.99.1" />
        <vers num="1.19.99.2" />
        <vers num="1.19.99.3" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers num="1.21-pre1" />
        <vers prev="1" num="1.23-pre1" />
        <vers num="1.24-pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0295" published="2010-02-03" name="CVE-2010-0295" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38036" source="BID" patch="1">38036</ref>
      <ref url="http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt" source="CONFIRM" patch="1">http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2010_01.txt</ref>
      <ref url="http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch" source="CONFIRM" patch="1">http://download.lighttpd.net/lighttpd/security/lighttpd-1.5_fix_slow_request_dos.patch</ref>
      <ref url="http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch" source="CONFIRM" patch="1">http://download.lighttpd.net/lighttpd/security/lighttpd-1.4.x_fix_slow_request_dos.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56038" source="XF">lighttpd-slow-request-dos(56038)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0172" source="VUPEN">ADV-2011-0172</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/01/8" source="MLIST">[oss-security] 20100202 lighttpd: slow request dos/oom attack [CVE-2010-0295]</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1987" source="DEBIAN">DSA-1987</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201006-17.xml" source="GENTOO">GLSA-201006-17</ref>
      <ref url="http://secunia.com/advisories/39765" source="SECUNIA">39765</ref>
      <ref url="http://secunia.com/advisories/38403" source="SECUNIA" adv="1">38403</ref>
      <ref url="http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2711" source="CONFIRM">http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2711</ref>
      <ref url="http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2710" source="CONFIRM">http://redmine.lighttpd.net/projects/lighttpd/repository/revisions/2710</ref>
      <ref url="http://redmine.lighttpd.net/issues/2147" source="CONFIRM">http://redmine.lighttpd.net/issues/2147</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html" source="SUSE">SUSE-SR:2010:003</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041307.html" source="FEDORA">FEDORA-2010-7643</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041296.html" source="FEDORA">FEDORA-2010-7611</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041264.html" source="FEDORA">FEDORA-2010-7636</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_0295_vulnerability_in" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_0295_vulnerability_in</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lighttpd" name="lighttpd">
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.15" />
        <vers num="1.4.16" />
        <vers num="1.4.17" />
        <vers num="1.4.18" />
        <vers num="1.4.19" />
        <vers num="1.4.2" />
        <vers num="1.4.20" />
        <vers num="1.4.21" />
        <vers num="1.4.22" />
        <vers num="1.4.23" />
        <vers num="1.4.24" />
        <vers prev="1" num="1.4.25" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0296" published="2010-06-01" name="CVE-2010-0296" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559579" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559579</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59240" source="XF">gnuclibrary-encodenamemacro-dos(59240)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0863" source="VUPEN">ADV-2011-0863</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1246" source="VUPEN" adv="1">ADV-2010-1246</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0012.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0012.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-944-1" source="UBUNTU">USN-944-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded" source="BUGTRAQ">20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0412.html" source="REDHAT">RHSA-2011:0412</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:112" source="MANDRIVA">MDVSA-2010:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:111" source="MANDRIVA">MDVSA-2010:111</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2058" source="DEBIAN">DSA-2058</ref>
      <ref url="http://sourceware.org/git/?p=glibc.git;a=commit;h=ab00f4eac8f4932211259ff87be83144f5211540" source="CONFIRM">http://sourceware.org/git/?p=glibc.git;a=commit;h=ab00f4eac8f4932211259ff87be83144f5211540</ref>
      <ref url="http://securitytracker.com/id?1024043" source="SECTRACK">1024043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201011-01.xml" source="GENTOO">GLSA-201011-01</ref>
      <ref url="http://secunia.com/advisories/46397" source="SECUNIA">46397</ref>
      <ref url="http://secunia.com/advisories/43830" source="SECUNIA">43830</ref>
      <ref url="http://secunia.com/advisories/39900" source="SECUNIA" adv="1">39900</ref>
      <ref url="http://frugalware.org/security/662" source="CONFIRM">http://frugalware.org/security/662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.1.6" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.9" />
        <vers num="2.10" />
        <vers num="2.10.1" />
        <vers num="2.11" />
        <vers prev="1" num="2.11.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0297" published="2010-02-12" name="CVE-2010-0297" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0088.html" source="REDHAT">RHSA-2010:0088</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=557025" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=557025</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56194" source="XF">kernel-usb-bo(56194)</ref>
      <ref url="http://www.securityfocus.com/bid/38158" source="BID">38158</ref>
      <ref url="http://www.mail-archive.com/kvm@vger.kernel.org/msg19596.html" source="MLIST">[kvm] 20090721 Re: KVM crashes when using certain USB device</ref>
      <ref url="http://www.mail-archive.com/kvm@vger.kernel.org/msg19581.html" source="MLIST">[kvm] 20090721 Re: KVM crashes when using certain USB device</ref>
      <ref url="http://www.mail-archive.com/kvm@vger.kernel.org/msg18447.html" source="MLIST">[kvm] 20090702 KVM crashes when using certain USB device</ref>
      <ref url="http://wiki.qemu.org/ChangeLog" source="CONFIRM">http://wiki.qemu.org/ChangeLog</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11786" source="OVAL">oval:org.mitre.oval:def:11786</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126527304127254&amp;w=2" source="MLIST">[oss-security] 20100204 Re: KVM possible security issues fixed</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126510479211473&amp;w=2" source="MLIST">[oss-security] 20100202 KVM possible security issues fixed</ref>
      <ref url="http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=babd03fde68093482528010a5435c14ce9128e3f" source="CONFIRM">http://git.savannah.gnu.org/cgit/qemu.git/commit/?id=babd03fde68093482528010a5435c14ce9128e3f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qemu" name="qemu">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers prev="1" num="0.11.0" />
        <vers num="0.11.0-rc0" />
        <vers num="0.11.0-rc1" />
        <vers num="0.11.0-rc2" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.1-5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0298" published="2010-02-12" name="CVE-2010-0298" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, a related issue to CVE-2010-0306.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT">RHSA-2010:0095</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0088.html" source="REDHAT">RHSA-2010:0088</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559091" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559091</ref>
      <ref url="http://www.securityfocus.com/bid/38158" source="BID">38158</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11335" source="OVAL">oval:org.mitre.oval:def:11335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0299" published="2010-02-22" name="CVE-2010-0299" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">openSUSE 11.2 installs the devtmpfs root directory with insecure permissions (1777), which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00002.html" source="SUSE" patch="1" adv="1">SUSE-SA:2010:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="opensuse">
        <vers num="11.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0300" published="2010-02-04" name="CVE-2010-0300" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cache.c in ircd-ratbox before 2.2.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a HELP command.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2010/dsa-1980" source="DEBIAN">DSA-1980</ref>
      <ref url="http://security.debian.org/pool/updates/main/i/ircd-ratbox/ircd-ratbox_2.2.8.dfsg-2+lenny1.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/i/ircd-ratbox/ircd-ratbox_2.2.8.dfsg-2+lenny1.diff.gz</ref>
      <ref url="http://secunia.com/advisories/38383" source="SECUNIA" adv="1">38383</ref>
      <ref url="http://secunia.com/advisories/38210" source="SECUNIA" adv="1">38210</ref>
      <ref url="http://lists.ratbox.org/pipermail/ircd-ratbox/2010-January/000891.html" source="MLIST">[ircd-ratbox] 20100125 ircd-ratbox-2.2.9 released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ircd-ratbox" name="ircd-ratbox">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4" edition="rc2" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.0" edition="beta1" />
        <vers num="2.1.0" edition="beta2" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.2.0" edition="rc1" />
        <vers num="2.2.0" edition="rc2" />
        <vers num="2.2.0" edition="rc3" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7.1" />
        <vers prev="1" num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0301" published="2010-02-04" name="CVE-2010-0301" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's home directory, which allows local users to gain privileges via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559681" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559681</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55980" source="XF">maildrop-group-priv-escalation(55980)</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1981" source="DEBIAN">DSA-1981</ref>
      <ref url="http://www.courier-mta.org/maildrop/changelog.html" source="CONFIRM">http://www.courier-mta.org/maildrop/changelog.html</ref>
      <ref url="http://securitytracker.com/id?1023515" source="SECTRACK">1023515</ref>
      <ref url="http://secunia.com/advisories/38374" source="SECUNIA" adv="1">38374</ref>
      <ref url="http://secunia.com/advisories/38367" source="SECUNIA" adv="1">38367</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126468618017829&amp;w=2" source="MLIST">[oss-security] 20100128 Re: CVE id request: maildrop</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126468551017070&amp;w=2" source="MLIST">[oss-security] 20100128 Re: CVE id request: maildrop</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126468324913920&amp;w=2" source="MLIST">[oss-security] 20100128 Re: CVE id request: maildrop</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126462927918840&amp;w=2" source="MLIST">[oss-security] 20100127 CVE id request: maildrop</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564601" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=564601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maildrop" name="maildrop">
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.51b" />
        <vers num="0.51c" />
        <vers num="0.54" />
        <vers num="0.54a" />
        <vers num="0.54b" />
        <vers num="0.55" />
        <vers num="0.55a" />
        <vers num="0.55b" />
        <vers num="0.55c" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.76" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7.0" />
        <vers num="1.8.1" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers prev="1" num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0302" published="2010-03-05" name="CVE-2010-0302" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3553.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0129.html" source="REDHAT">RHSA-2010:0129</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=557775" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=557775</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.ubuntu.com/usn/USN-906-1" source="UBUNTU">USN-906-1</ref>
      <ref url="http://www.securitytracker.com/id?1024124" source="SECTRACK">1024124</ref>
      <ref url="http://www.securityfocus.com/bid/38510" source="BID">38510</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:073" source="MANDRIVA">MDVSA-2010:073</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/38979" source="SECUNIA">38979</ref>
      <ref url="http://secunia.com/advisories/38927" source="SECUNIA">38927</ref>
      <ref url="http://secunia.com/advisories/38785" source="SECUNIA">38785</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11216" source="OVAL">oval:org.mitre.oval:def:11216</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037174.html" source="FEDORA">FEDORA-2010-2743</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://cups.org/str.php?L3490" source="CONFIRM">http://cups.org/str.php?L3490</ref>
      <ref url="http://cups.org/articles.php?L596" source="CONFIRM">http://cups.org/articles.php?L596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.3.10" />
        <vers num="1.3.7" />
        <vers num="1.3.9" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0303" published="2010-02-04" name="CVE-2010-0303" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash) via a ":help \t" private message to the MemoServ service.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.debian.org/pool/updates/main/h/hybserv/hybserv_1.9.2-4+lenny2.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/h/hybserv/hybserv_1.9.2-4+lenny2.diff.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55992" source="XF">hybserv2-privatemessage-dos(55992)</ref>
      <ref url="http://www.securityfocus.com/bid/38006" source="BID">38006</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1982" source="DEBIAN">DSA-1982</ref>
      <ref url="http://secunia.com/advisories/38352" source="SECUNIA" adv="1">38352</ref>
      <ref url="http://secunia.com/advisories/38350" source="SECUNIA" adv="1">38350</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126476591925300&amp;w=2" source="MLIST">[oss-security] 20100129 Re: CVE id: hybserv</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550389" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=550389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dinko_korunic" name="hybserv2">
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0304" published="2010-02-03" name="CVE-2010-0304" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0239" source="VUPEN" patch="1" adv="1">ADV-2010-0239</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55951" source="XF">wireshark-lwres-bo(55951)</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2010-02.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2010-02.html</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2010-01.html" source="CONFIRM">http://www.wireshark.org/security/wnpa-sec-2010-01.html</ref>
      <ref url="http://www.securitytracker.com/id?1023516" source="SECTRACK">1023516</ref>
      <ref url="http://www.securityfocus.com/bid/37985" source="BID">37985</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/29/4" source="MLIST">[oss-security] 20100129 Re: CVE id request: Wireshark</ref>
      <ref url="http://www.metasploit.com/modules/exploit/multi/misc/wireshark_lwres_getaddrbyname" source="MISC">http://www.metasploit.com/modules/exploit/multi/misc/wireshark_lwres_getaddrbyname</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:031" source="MANDRIVA">MDVSA-2010:031</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1983" source="DEBIAN">DSA-1983</ref>
      <ref url="http://secunia.com/advisories/38829" source="SECUNIA">38829</ref>
      <ref url="http://secunia.com/advisories/38348" source="SECUNIA" adv="1">38348</ref>
      <ref url="http://secunia.com/advisories/38257" source="SECUNIA" adv="1">38257</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9933" source="OVAL">oval:org.mitre.oval:def:9933</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8490" source="OVAL">oval:org.mitre.oval:def:8490</ref>
      <ref url="http://osvdb.org/61987" source="OSVDB">61987</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036415.html" source="FEDORA">FEDORA-2010-3556</ref>
      <ref url="http://anonsvn.wireshark.org/viewvc/trunk-1.2/epan/dissectors/packet-lwres.c?view=diff&amp;r1=31596&amp;r2=28492&amp;diff_format=h" source="MISC">http://anonsvn.wireshark.org/viewvc/trunk-1.2/epan/dissectors/packet-lwres.c?view=diff&amp;r1=31596&amp;r2=28492&amp;diff_format=h</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.9.15" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0305" published="2010-02-03" name="CVE-2010-0305" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/29/5" source="MLIST" patch="1">[oss-security] 20100129 Re: CVE Request -- ejabberd</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/29/1" source="MLIST" patch="1">[oss-security] 20100129 CVE Request -- ejabberd</ref>
      <ref url="https://support.process-one.net/browse/EJAB-1173" source="CONFIRM">https://support.process-one.net/browse/EJAB-1173</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56025" source="XF">ejabberd-client2server-dos(56025)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0894" source="VUPEN">ADV-2010-0894</ref>
      <ref url="http://www.securityfocus.com/bid/38003" source="BID">38003</ref>
      <ref url="http://www.osvdb.org/62066" source="OSVDB">62066</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2033" source="DEBIAN">DSA-2033</ref>
      <ref url="http://secunia.com/advisories/39423" source="SECUNIA">39423</ref>
      <ref url="http://secunia.com/advisories/38337" source="SECUNIA" adv="1">38337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="process-one" name="ejabberd">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.8" />
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.1.0" />
        <vers num="1.1.1.1" />
        <vers num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="2.0.0" edition="beta1" />
        <vers num="2.0.0" edition="rc1" />
        <vers num="2.0.1_2" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers prev="1" num="2.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0306" published="2010-02-12" name="CVE-2010-0306" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch, a related issue to CVE-2010-0298.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT">RHSA-2010:0095</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0088.html" source="REDHAT">RHSA-2010:0088</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=560654" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=560654</ref>
      <ref url="http://www.securityfocus.com/bid/38158" source="BID">38158</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/38499" source="SECUNIA" adv="1">38499</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA" adv="1">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10953" source="OVAL">oval:org.mitre.oval:def:10953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kvm_qumranet" name="kvm">
        <vers num="83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0307" published="2010-02-17" name="CVE-2010-0307" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0146.html" source="REDHAT">RHSA-2010:0146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=560547" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=560547</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.securityfocus.com/bid/38027" source="BID">38027</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0771.html" source="REDHAT">RHSA-2010:0771</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0398.html" source="REDHAT">RHSA-2010:0398</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/04/9" source="MLIST">[oss-security] 20100204 Re: CVE request - kernel: DoS on x86_64</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/04/1" source="MLIST">[oss-security] 20100203 Re: CVE request - kernel: DoS on x86_64</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/01/5" source="MLIST">[oss-security] 20100201 Re: CVE request - kernel: DoS on x86_64</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/01/1" source="MLIST">[oss-security] 20100201 CVE request - kernel: DoS on x86_64</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:066" source="MANDRIVA">MDVSA-2010:066</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.8" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.8</ref>
      <ref url="http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of,20100202,15754.html" source="MISC">http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of,20100202,15754.html</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100088287" source="CONFIRM">http://support.avaya.com/css/P8/documents/100088287</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39649" source="SECUNIA">39649</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10870" source="OVAL">oval:org.mitre.oval:def:10870</ref>
      <ref url="http://marc.info/?t=126466700200002&amp;r=1&amp;w=2" source="CONFIRM">http://marc.info/?t=126466700200002&amp;r=1&amp;w=2</ref>
      <ref url="http://marc.info/?l=linux-mm&amp;m=126466407724382&amp;w=2" source="MLIST">[linux-mm] 20100128 DoS on x86_64</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html" source="FEDORA">FEDORA-2010-1787</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=221af7f87b97431e3ee21ce4b0e77d5411cf1549" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=221af7f87b97431e3ee21ce4b0e77d5411cf1549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="e1000">
        <vers num="5.2.22" />
        <vers num="5.2.30.1" />
        <vers num="5.2.52" />
        <vers num="5.3.19" />
        <vers num="5.4.11" />
        <vers num="5.5.4" />
        <vers num="5.6.10" />
        <vers num="5.6.10.1" />
        <vers num="5.7.6" />
        <vers num="6.0.54" />
        <vers num="6.0.60" />
        <vers num="6.1.16" />
        <vers num="6.2.15" />
        <vers num="6.3.9" />
        <vers num="7.0.33" />
        <vers num="7.0.41" />
        <vers num="7.1.9" />
        <vers num="7.2.7" />
        <vers num="7.2.9" />
        <vers num="7.3.15" />
        <vers num="7.3.20" />
        <vers num="7.4.27" />
        <vers prev="1" num="7.4.35" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers prev="1" num="2.6.32.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0308" published="2010-02-03" name="CVE-2010-0308" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9163.patch" source="MISC" patch="1">http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9163.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56001" source="XF">squid-dns-dos(56001)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0260" source="VUPEN" adv="1">ADV-2010-0260</ref>
      <ref url="http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-9853.patch" source="MISC">http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-9853.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/HEAD/changesets/12597.patch" source="MISC">http://www.squid-cache.org/Versions/v2/HEAD/changesets/12597.patch</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2010_1.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2010_1.txt</ref>
      <ref url="http://www.securitytracker.com/id?1023520" source="SECTRACK">1023520</ref>
      <ref url="http://www.securityfocus.com/bid/37522" source="BID">37522</ref>
      <ref url="http://secunia.com/advisories/38455" source="SECUNIA" adv="1">38455</ref>
      <ref url="http://secunia.com/advisories/38451" source="SECUNIA" adv="1">38451</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11270" source="OVAL">oval:org.mitre.oval:def:11270</ref>
      <ref url="http://osvdb.org/62044" source="OSVDB">62044</ref>
      <ref url="http://events.ccc.de/congress/2009/Fahrplan/attachments/1483_26c3_ipv4_fuckups.pdf" source="MISC">http://events.ccc.de/congress/2009/Fahrplan/attachments/1483_26c3_ipv4_fuckups.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid-cache" name="squid">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="3.0" />
        <vers num="3.0.stable1" />
        <vers num="3.0.stable11" />
        <vers num="3.0.stable12" />
        <vers num="3.0.stable13" />
        <vers num="3.0.stable14" />
        <vers num="3.0.stable15" />
        <vers num="3.0.stable16" />
        <vers num="3.0.stable17" />
        <vers num="3.0.stable18" />
        <vers num="3.0.stable19" />
        <vers num="3.0.stable2" />
        <vers num="3.0.stable20" />
        <vers num="3.0.stable21" />
        <vers num="3.0.stable22" />
        <vers num="3.0.stable3" />
        <vers num="3.0.stable4" />
        <vers num="3.0.stable5" />
        <vers num="3.0.stable6" />
        <vers num="3.0.stable7" />
        <vers num="3.0.stable8" />
        <vers num="3.0.stable9" />
        <vers num="3.1" />
        <vers num="3.1.0.1" />
        <vers num="3.1.0.10" />
        <vers num="3.1.0.11" />
        <vers num="3.1.0.12" />
        <vers num="3.1.0.13" />
        <vers num="3.1.0.14" />
        <vers num="3.1.0.15" />
        <vers num="3.1.0.2" />
        <vers num="3.1.0.3" />
        <vers num="3.1.0.4" />
        <vers num="3.1.0.5" />
        <vers num="3.1.0.6" />
        <vers num="3.1.0.7" />
        <vers num="3.1.0.8" />
        <vers num="3.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0309" published="2010-02-12" name="CVE-2010-0309" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure, which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0095</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0088.html" source="REDHAT" adv="1">RHSA-2010:0088</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=560887" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=560887</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.securityfocus.com/bid/38158" source="BID">38158</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/02/4" source="MLIST">[oss-security] 20100202 Re: CVE request - kvm: cat /dev/port in the guest can cause host DoS</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/02/1" source="MLIST">[oss-security] 20100202 CVE request - kvm: cat /dev/port in the guest can cause host DoS</ref>
      <ref url="http://www.mail-archive.com/kvm@vger.kernel.org/msg28002.html" source="MLIST">[kvm] 20100129 KVM: PIT: control word is write-only</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11095" source="OVAL">oval:org.mitre.oval:def:11095</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0310" published="2010-01-14" name="CVE-2010-0310" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-143502-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-143502-01-1</ref>
      <ref url="http://www.securityfocus.com/bid/37754" source="BID">37754</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-275410-1" source="SUNALERT" adv="1">275410</ref>
      <ref url="http://securitytracker.com/id?1023448" source="SECTRACK">1023448</ref>
      <ref url="http://secunia.com/advisories/38129" source="SECUNIA" adv="1">38129</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8444" source="OVAL">oval:org.mitre.oval:def:8444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0311" published="2010-01-14" name="CVE-2010-0311" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55572" source="XF">jsim-unspecified-security-bypass(55572)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0108" source="VUPEN" adv="1">ADV-2010-0108</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-275010-1" source="SUNALERT" adv="1">275010</ref>
      <ref url="http://securitytracker.com/id?1023447" source="SECTRACK">1023447</ref>
      <ref url="http://secunia.com/advisories/38130" source="SECUNIA" adv="1">38130</ref>
      <ref url="http://osvdb.org/61658" source="OSVDB">61658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_server">
        <vers num="8.1.0.5" />
        <vers num="8.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0312" published="2010-01-14" name="CVE-2010-0312" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1023433" source="SECTRACK">1023433</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/tivoli-directory-server-62-doextendedop.html" source="MISC">http://intevydis.blogspot.com/2010/01/tivoli-directory-server-62-doextendedop.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_directory_server">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0313" published="2010-01-14" name="CVE-2010-0313" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55511" source="XF">jsds-coregetproxyauthdn-dos(55511)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0085" source="VUPEN" adv="1">ADV-2010-0085</ref>
      <ref url="http://www.securityfocus.com/bid/37699" source="BID">37699</ref>
      <ref url="http://securitytracker.com/id?1023431" source="SECTRACK">1023431</ref>
      <ref url="http://secunia.com/advisories/37978" source="SECUNIA" adv="1">37978</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-directory-server-70.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-directory-server-70.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0314" published="2010-01-14" name="CVE-2010-0314" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html" source="MISC">http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0315" published="2010-01-14" name="CVE-2010-0315" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=33683" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=33683</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56215" source="XF">googlechrome-iframe-info-disc(56215)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55683" source="XF">google-chrome-href-info-disclosure(55683)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://trac.webkit.org/changeset/53607" source="CONFIRM">http://trac.webkit.org/changeset/53607</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14452" source="OVAL">oval:org.mitre.oval:def:14452</ref>
      <ref url="http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html" source="MISC">http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=32309" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=32309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0316" published="2010-01-15" name="CVE-2010-0316" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SKP file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0133" source="VUPEN" adv="1">ADV-2010-0133</ref>
      <ref url="http://sketchup.google.com/support/bin/answer.py?hl=en&amp;answer=141303" source="CONFIRM">http://sketchup.google.com/support/bin/answer.py?hl=en&amp;answer=141303</ref>
      <ref url="http://secunia.com/advisories/38187" source="SECUNIA" adv="1">38187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="google_sketchup">
        <vers num="7.0" />
        <vers num="7.0.10247" />
        <vers num="7.1.4871" />
        <vers num="7.1.6087" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0317" published="2010-01-15" name="CVE-2010-0317" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55389" source="XF">netware-afptcp-dos(55389)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0041" source="VUPEN" adv="1">ADV-2010-0041</ref>
      <ref url="http://www.securitytracker.com/id?1023400" source="SECTRACK">1023400</ref>
      <ref url="http://www.securityfocus.com/bid/37616" source="BID">37616</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508731/100/0/threaded" source="BUGTRAQ">20100105 {PRL} Novell Netware CIFS And AFP Remote Memory Consumption DoS</ref>
      <ref url="http://www.exploit-db.com/exploits/11009" source="EXPLOIT-DB">11009</ref>
      <ref url="http://secunia.com/advisories/38114" source="SECUNIA" adv="1">38114</ref>
      <ref url="http://protekresearch.blogspot.com/2010/01/prl-cifsnlm-memory-consumption-denial.html" source="MISC">http://protekresearch.blogspot.com/2010/01/prl-cifsnlm-memory-consumption-denial.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware">
        <vers num="6.5" edition="sp8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0318" published="2010-01-15" name="CVE-2010-0318" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-10:03.zfs.asc" source="FREEBSD" patch="1" adv="1">FreeBSD-SA-10:03</ref>
      <ref url="http://www.securitytracker.com/id?1023407" source="SECTRACK">1023407</ref>
      <ref url="http://www.securityfocus.com/bid/37657" source="BID">37657</ref>
      <ref url="http://secunia.com/advisories/38124" source="SECUNIA" adv="1">38124</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0319" published="2010-01-15" name="CVE-2010-0319" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55549" source="XF">docmint-index-xss(55549)</ref>
      <ref url="http://www.securityfocus.com/bid/37721" source="BID">37721</ref>
      <ref url="http://www.exploit-db.com/exploits/11119" source="EXPLOIT-DB">11119</ref>
      <ref url="http://secunia.com/advisories/38149" source="SECUNIA" adv="1">38149</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/docmintcms-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/docmintcms-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="docmint" name="docmint">
        <vers num="1.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0320" published="2010-01-15" name="CVE-2010-0320" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in submitlink.php in Glitter Central Script allows remote attackers to inject arbitrary web script or HTML via the catid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55537" source="XF">glittercentral-submitlink-xss(55537)</ref>
      <ref url="http://www.osvdb.org/61632" source="OSVDB">61632</ref>
      <ref url="http://www.exploit-db.com/exploits/11108" source="EXPLOIT-DB">11108</ref>
      <ref url="http://secunia.com/advisories/38146" source="SECUNIA" adv="1">38146</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/glittercentral-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/glittercentral-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x10media" name="glitter_central_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0321" published="2010-01-15" name="CVE-2010-0321" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55500" source="XF">jamit-jobboard-index-xss(55500)</ref>
      <ref url="http://www.securityfocus.com/bid/37701" source="BID">37701</ref>
      <ref url="http://www.exploit-db.com/exploits/11073" source="EXPLOIT-DB">11073</ref>
      <ref url="http://secunia.com/advisories/32797" source="SECUNIA" adv="1">32797</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/jamitjobboard-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/jamitjobboard-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jamit" name="jamit_job_board">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0322" published="2010-01-15" name="CVE-2010-0322" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/info/ChangeLog/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/info/ChangeLog/</ref>
      <ref url="http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthias_karr" name="mk_anydropdownmenu">
        <vers num="0.3.10" />
        <vers num="0.3.12" />
        <vers num="0.3.13" />
        <vers num="0.3.23" />
        <vers num="0.3.25" />
        <vers num="0.3.26" />
        <vers num="0.3.27" />
        <vers prev="1" num="0.3.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0323" published="2010-01-15" name="CVE-2010-0323" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Photo Book (goof_fotoboek) extension 1.7.14 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/goof_fotoboek/1.7.15/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/goof_fotoboek/1.7.15/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arco_van_geest" name="goof_fotoboek">
        <vers num="1.2.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.5.1" />
        <vers num="1.6.1" />
        <vers num="1.6.4" />
        <vers num="1.7.0" />
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.13" />
        <vers prev="1" num="1.7.14" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.7" />
        <vers num="1.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0324" published="2010-01-15" name="CVE-2010-0324" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/ref_list/1.0.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/ref_list/1.0.2/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="patrick_bauerochse" name="ref_list">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0325" published="2010-01-15" name="CVE-2010-0325" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SB Folderdownload (sb_folderdownload) extension 0.2.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/sb_folderdownload/0.2.3/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/sb_folderdownload/0.2.3/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sebastian_baumann" name="sb_folderdownload">
        <vers num="0.1.1" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers prev="1" num="0.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0326" published="2010-01-15" name="CVE-2010-0326" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Developer log (devlog) extension 2.9.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/devlog/2.9.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/devlog/2.9.2/</ref>
      <ref url="http://secunia.com/advisories/38164" source="SECUNIA" adv="1">38164</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francois_suter" name="devlog">
        <vers num="2.0.0" />
        <vers num="2.1.0" />
        <vers num="2.2.0" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.4.0" />
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.7.0" />
        <vers num="2.8.0" />
        <vers num="2.9.0" />
        <vers prev="1" num="2.9.1" />
      </prod>
      <prod vendor="rene_fritz" name="devlog">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0327" published="2010-01-15" name="CVE-2010-0327" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/kj_imagelightbox2/2.0.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/kj_imagelightbox2/2.0.2/</ref>
      <ref url="http://secunia.com/advisories/38165" source="SECUNIA" adv="1">38165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julian_kleinhans" name="kj_imagelightbox2">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers prev="1" num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0328" published="2010-01-15" name="CVE-2010-0328" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Unit Converter (cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/cs2_unitconv/1.0.5/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/cs2_unitconv/1.0.5/</ref>
      <ref url="http://secunia.com/advisories/38166" source="SECUNIA" adv="1">38166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rastislav_birka" name="cs2_unitconv">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0329" published="2010-01-15" name="CVE-2010-0329" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the "SQL selection field" and "typoscript."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/powermail/1.5.2/info/changelog.txt/" source="CONFIRM">http://typo3.org/extensions/repository/view/powermail/1.5.2/info/changelog.txt/</ref>
      <ref url="http://typo3.org/extensions/repository/view/powermail/1.5.2/" source="CONFIRM">http://typo3.org/extensions/repository/view/powermail/1.5.2/</ref>
      <ref url="http://secunia.com/advisories/38167" source="SECUNIA" adv="1">38167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_kellner" name="powermail">
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.15" />
        <vers num="1.4.16" />
        <vers num="1.4.17" />
        <vers num="1.4.18" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5.0" />
        <vers prev="1" num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0330" published="2010-01-15" name="CVE-2010-0330" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Googlemaps for tt_news (jf_easymaps) extension 1.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/jf_easymaps/1.0.3/" source="MISC">http://typo3.org/extensions/repository/view/jf_easymaps/1.0.3/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="julian_fries" name="jf_easymaps">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0331" published="2010-01-15" name="CVE-2010-0331" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_tannhaeuser" name="tv21_talkshow">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0332" published="2010-01-15" name="CVE-2010-0332" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_tannhaeuser" name="tv21_talkshow">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0333" published="2010-01-15" name="CVE-2010-0333" modified="2011-07-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Helpdesk (mg_help) extension 1.1.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthias_graubner" name="mg_help">
        <vers num="0.1.0" />
        <vers num="0.2.0" />
        <vers num="1.0.0" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers prev="1" num="1.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0334" published="2010-01-15" name="CVE-2010-0334" modified="2011-07-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_cifuentes" name="vote_for_tt_news">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0335" published="2010-01-15" name="CVE-2010-0335" modified="2011-07-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_cifuentes" name="vote_for_tt_news">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0336" published="2010-01-15" name="CVE-2010-0336" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="kiddog_mysqldumper">
        <vers prev="1" num="0.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0337" published="2010-01-15" name="CVE-2010-0337" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="dl3_tt_news_alerts">
        <vers prev="1" num="0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0338" published="2010-01-15" name="CVE-2010-0338" modified="2011-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="ttpedit">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0339" published="2010-01-15" name="CVE-2010-0339" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="vm19_userlinks">
        <vers prev="1" num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0340" published="2010-01-15" name="CVE-2010-0340" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="mjseventpro">
        <vers prev="1" num="0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0341" published="2010-01-15" name="CVE-2010-0341" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="bb_simplejobs">
        <vers prev="1" num="0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0342" published="2010-01-15" name="CVE-2010-0342" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="job_reports">
        <vers prev="1" num="0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0343" published="2010-01-15" name="CVE-2010-0343" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="pb_clanlist">
        <vers num="0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0344" published="2010-01-15" name="CVE-2010-0344" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="zak_store_management">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0345" published="2010-01-15" name="CVE-2010-0345" modified="2010-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="majordomo">
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0346" published="2010-01-15" name="CVE-2010-0346" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="mimi_tipfriends">
        <vers prev="1" num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0347" published="2010-01-15" name="CVE-2010-0347" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the VD / Geomap (vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="vd_gemomap">
        <vers prev="1" num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0348" published="2010-01-15" name="CVE-2010-0348" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://webcal.c-3.jp/zeijakusei.html" source="CONFIRM">http://webcal.c-3.jp/zeijakusei.html</ref>
      <ref url="http://secunia.com/advisories/38135" source="SECUNIA" adv="1">38135</ref>
      <ref url="http://osvdb.org/61630" source="OSVDB">61630</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000003.html" source="JVNDB">JVNDB-2010-000003</ref>
      <ref url="http://jvn.jp/en/jp/JVN22247093/index.html" source="JVN">JVN#22247093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="c-3.co.jp" name="webcalenderc3">
        <vers num="0.31" edition="s2" />
        <vers prev="1" num="0.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0349" published="2010-01-15" name="CVE-2010-0349" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/61629" source="OSVDB">61629</ref>
      <ref url="http://webcal.c-3.jp/zeijakusei.html" source="MISC" adv="1">http://webcal.c-3.jp/zeijakusei.html</ref>
      <ref url="http://secunia.com/advisories/38135" source="SECUNIA" adv="1">38135</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000002.html" source="JVNDB">JVNDB-2010-000002</ref>
      <ref url="http://jvn.jp/en/jp/JVN33977065/index.html" source="JVN">JVN#33977065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="c-3.co.jp" name="webcalenderc3">
        <vers num="0.31" edition="s2" />
        <vers prev="1" num="0.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0350" published="2010-01-15" name="CVE-2010-0350" modified="2011-05-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Photo Book (goof_fotoboek) extension 1.7.14 and earlier for TYPO3 has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/</ref>
      <ref url="http://typo3.org/extensions/repository/view/goof_fotoboek/1.7.15/" source="CONFIRM">http://typo3.org/extensions/repository/view/goof_fotoboek/1.7.15/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arco_van_geest" name="goof_fotoboek">
        <vers num="1.2.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.5.1" />
        <vers num="1.6.1" />
        <vers num="1.6.4" />
        <vers num="1.7.0" />
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.13" />
        <vers prev="1" num="1.7.14" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.7" />
        <vers num="1.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0356" published="2010-01-18" name="CVE-2010-0356" modified="2011-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55536" source="XF">movieplayer-drawtext-activex-bo(55536)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0093" source="VUPEN" adv="1">ADV-2010-0093</ref>
      <ref url="http://www.shinnai.net/exploits/X6hU4E0E7P5H3qH5yXrn.txt" source="MISC">http://www.shinnai.net/exploits/X6hU4E0E7P5H3qH5yXrn.txt</ref>
      <ref url="http://secunia.com/advisories/38156" source="SECUNIA" adv="1">38156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viscomsoft" name="movie_player_pro_sdk_activex">
        <vers num="6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0357" published="2010-01-20" name="CVE-2010-0357" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM02704" source="AIXAPAR" patch="1">PM02704</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55663" source="XF">lotusweb-login-xss(55663)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0149" source="VUPEN" adv="1">ADV-2010-0149</ref>
      <ref url="http://www.securityfocus.com/bid/37825" source="BID">37825</ref>
      <ref url="http://www.osvdb.org/61711" source="OSVDB">61711</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM04647" source="AIXAPAR" adv="1">PM04647</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM03233" source="AIXAPAR">PM03233</ref>
      <ref url="http://securitytracker.com/id?1023463" source="SECTRACK">1023463</ref>
      <ref url="http://secunia.com/advisories/38174" source="SECUNIA" adv="1">38174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_web_content_management">
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0358" published="2010-01-20" name="CVE-2010-0358" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1023456" source="SECTRACK">1023456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0" />
        <vers num="8.5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0359" published="2010-01-20" name="CVE-2010-0359" modified="2010-01-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0147" source="VUPEN" adv="1">ADV-2010-0147</ref>
      <ref url="http://www.securityfocus.com/bid/37829" source="BID">37829</ref>
      <ref url="http://www.osvdb.org/61699" source="OSVDB">61699</ref>
      <ref url="http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released" source="CONFIRM">http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released</ref>
      <ref url="http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES" source="CONFIRM" adv="1">http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES</ref>
      <ref url="http://securitytracker.com/id?1023465" source="SECTRACK">1023465</ref>
      <ref url="http://secunia.com/advisories/38056" source="SECUNIA" adv="1">38056</ref>
      <ref url="http://intevydis.com/vd-list.shtml" source="MISC">http://intevydis.com/vd-list.shtml</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/zeus-web-server-ssl2clienthello.html" source="MISC">http://intevydis.blogspot.com/2010/01/zeus-web-server-ssl2clienthello.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus" name="zeus_web_server">
        <vers num="4.3r5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0360" published="2010-01-20" name="CVE-2010-0360" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://intevydis.com/vd-list.shtml" source="MISC">http://intevydis.com/vd-list.shtml</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-trace.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-trace.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0361" published="2010-01-20" name="CVE-2010-0361" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-webdav.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-webdav.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0362" published="2010-01-20" name="CVE-2010-0362" modified="2011-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES" source="CONFIRM" patch="1">http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus" name="zeus_web_server">
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.4" />
        <vers num="4.1" edition="r1" />
        <vers num="4.2" edition="r2" />
        <vers prev="1" num="4.3" edition="r3" />
        <vers prev="1" num="4.3" edition="r4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0363" published="2010-01-20" name="CVE-2010-0363" modified="2010-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Zeus Web Server before 4.3r5, when SSL is enabled for the admin server, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2002-1785.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES" source="CONFIRM">http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeus" name="zeus_web_server">
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="4.1" />
        <vers num="4.1r1" />
        <vers num="4.2" />
        <vers num="4.2r2" />
        <vers num="4.3" />
        <vers num="4.3r3" />
        <vers prev="1" num="4.3r4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0364" published="2010-01-21" name="CVE-2010-0364" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55717" source="XF">vlcmediaplayer-asas-bo(55717)</ref>
      <ref url="http://www.securityfocus.com/bid/37832" source="BID">37832</ref>
      <ref url="http://www.exploit-db.com/exploits/11174" source="EXPLOIT-DB">11174</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14342" source="OVAL">oval:org.mitre.oval:def:14342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0365" published="2010-01-21" name="CVE-2010-0365" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via the order parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55739" source="XF">bitsvideo-search-xss(55739)</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt</ref>
      <ref url="http://secunia.com/advisories/38252" source="SECUNIA" adv="1">38252</ref>
      <ref url="http://osvdb.org/61827" source="OSVDB">61827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitscripts" name="bits_video_script">
        <vers num="2.04" />
        <vers num="2.05" edition="gold_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0366" published="2010-01-21" name="CVE-2010-0366" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55738" source="XF">bitsvideo-addvideo-file-upload(55738)</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt</ref>
      <ref url="http://secunia.com/advisories/38252" source="SECUNIA" adv="1">38252</ref>
      <ref url="http://osvdb.org/61826" source="OSVDB">61826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitscripts" name="bits_video_script">
        <vers num="2.04" />
        <vers num="2.05" edition="gold_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0367" published="2010-01-21" name="CVE-2010-0367" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[template] parameter to (1) showcasesearch.php and (2) showcase2search.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55740" source="XF">bitsvideo-showcasesearch-file-include(55740)</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/bitsvs-xssuploadrfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitscripts" name="bits_video_script">
        <vers num="2.04" />
        <vers num="2.05" edition="gold_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0370" published="2010-01-21" name="CVE-2010-0370" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37782" source="BID" patch="1">37782</ref>
      <ref url="http://www.osvdb.org/61682" source="OSVDB" patch="1">61682</ref>
      <ref url="http://drupal.org/node/683598" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/683598</ref>
      <ref url="http://drupal.org/node/683586" source="CONFIRM" patch="1">http://drupal.org/node/683586</ref>
      <ref url="http://drupal.org/node/683584" source="CONFIRM" patch="1">http://drupal.org/node/683584</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55606" source="XF">nodeblocks-titles-xss(55606)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508933/100/0/threaded" source="BUGTRAQ">20100114 XSS Vulnerability in Drupal's Node Blocks contributed module (6.x-1.3 and 5.x-1.1)</ref>
      <ref url="http://secunia.com/advisories/38186" source="SECUNIA" adv="1">38186</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/drupalnb-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/drupalnb-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roger_lopez" name="nodeblock">
        <vers prev="1" num="5.x-1.1" />
      </prod>
      <prod vendor="thomas_turnbull" name="nodeblock">
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers prev="1" num="6.x-1.3" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0371" published="2010-01-21" name="CVE-2010-0371" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gall and (2) levela parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55704" source="XF">hitmaan-index-xss(55704)</ref>
      <ref url="http://secunia.com/advisories/38234" source="SECUNIA" adv="1">38234</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/galleriehitmaaan-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/galleriehitmaaan-xss.txt</ref>
      <ref url="http://osvdb.org/61801" source="OSVDB">61801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitmaaan" name="hitmaaan_gallery">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0372" published="2010-01-21" name="CVE-2010-0372" modified="2011-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55664" source="XF">articlemanager-index-sql-injection(55664)</ref>
      <ref url="http://www.securityfocus.com/bid/37799" source="BID">37799</ref>
      <ref url="http://www.exploit-db.com/exploits/11140" source="EXPLOIT-DB">11140</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlaarticlemanager-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlaarticlemanager-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hong_chuyen" name="com_articlemanager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0373" published="2010-01-21" name="CVE-2010-0373" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55696" source="XF">libros-index-sql-injection(55696)</ref>
      <ref url="http://www.exploit-db.com/exploits/11178" source="EXPLOIT-DB">11178</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlalibros-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlalibros-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_libros">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0374" published="2010-01-21" name="CVE-2010-0374" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55662" source="XF">marketplace-index-xss(55662)</ref>
      <ref url="http://www.securityfocus.com/bid/37819" source="BID">37819</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/joomlamarketplace-xss.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/joomlamarketplace-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codingfish" name="com_marketplace">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0375" published="2010-01-21" name="CVE-2010-0375" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55518" source="XF">phpcalendars-productlist-sql-injection(55518)</ref>
      <ref url="http://www.securityfocus.com/bid/40757" source="BID">40757</ref>
      <ref url="http://www.osvdb.org/61617" source="OSVDB">61617</ref>
      <ref url="http://www.exploit-db.com/exploits/11082" source="EXPLOIT-DB">11082</ref>
      <ref url="http://secunia.com/advisories/38036" source="SECUNIA" adv="1">38036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jce-tech" name="php_calendars_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0376" published="2010-01-21" name="CVE-2010-0376" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter.  NOTE: this issue is reportedly resultant from a forced SQL error message that occurs from exploitation of CVE-2010-0375.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55517" source="XF">phpcalendars-productlist-xss(55517)</ref>
      <ref url="http://www.securityfocus.com/bid/40391" source="BID">40391</ref>
      <ref url="http://www.exploit-db.com/exploits/11082" source="EXPLOIT-DB">11082</ref>
      <ref url="http://secunia.com/advisories/38036" source="SECUNIA" adv="1">38036</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpcalendars-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpcalendars-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jce-tech" name="php_calendars_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0377" published="2010-01-21" name="CVE-2010-0377" modified="2010-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38245" source="SECUNIA" adv="1">38245</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpmyspace-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpmyspace-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyspace" name="phpmyspace">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":gold" />
        <vers num="8.10" edition="" />
        <vers num="8.10" edition=":gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0378" published="2010-01-21" name="CVE-2010-0378" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/416.html

CWE-416 Use-After Free Vulnerability</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.microsoft.com/technet/security/advisory/979267.mspx

"	
Suggested Actions

Perform one or both of the following steps:
•	

Uninstall the Adobe Flash Player version 6.
•	

Install the most current version of Flash Player available from Adobe."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/204889" source="CERT-VN">VU#204889</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/979267.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/979267.mspx</ref>
      <ref url="http://securitytracker.com/id?1023435" source="SECTRACK">1023435</ref>
      <ref url="http://secunia.com/secunia_research/2007-77/" source="MISC" adv="1">http://secunia.com/secunia_research/2007-77/</ref>
      <ref url="http://secunia.com/advisories/27105" source="SECUNIA" adv="1">27105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7580" source="OVAL">oval:org.mitre.oval:def:7580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_player">
        <vers num="6.0.79" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0379" published="2010-01-21" name="CVE-2010-0379" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and SP3, might allow remote attackers to execute arbitrary code via unspecified vectors that are not related to the use-after-free "Movie Unloading Vulnerability" (CVE-2010-0378).  NOTE: due to lack of details, it is not clear whether this overlaps any other CVE item.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/advisory/979267.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/979267.mspx</ref>
      <ref url="http://securitytracker.com/id?1023435" source="SECTRACK">1023435</ref>
      <ref url="http://secunia.com/advisories/27105" source="SECUNIA" adv="1">27105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14146" source="OVAL">oval:org.mitre.oval:def:14146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_player">
        <vers num="6.0.21.0" />
        <vers num="6.0.79" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0380" published="2010-01-22" name="CVE-2010-0380" modified="2010-01-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request.  NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11082" source="EXPLOIT-DB">11082</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpcalendars-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpcalendars-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jce-tech" name="php_calendars_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0381" published="2010-01-22" name="CVE-2010-0381" modified="2010-01-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a show_stats action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38245" source="SECUNIA" adv="1">38245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyspace" name="phpmyspace">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":gold" />
        <vers num="8.10" edition="" />
        <vers num="8.10" edition=":gold" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0382" published="2010-01-22" name="CVE-2010-0382" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819.  NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.isc.org/advisories/CVE-2009-4022v6" source="CONFIRM" adv="1">https://www.isc.org/advisories/CVE-2009-4022v6</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1352" source="VUPEN">ADV-2010-1352</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0622" source="VUPEN">ADV-2010-0622</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2054" source="DEBIAN">DSA-2054</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0018</ref>
      <ref url="http://secunia.com/advisories/40086" source="SECUNIA">40086</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7086" source="OVAL">oval:org.mitre.oval:def:7086</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6665" source="OVAL">oval:org.mitre.oval:def:6665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11753" source="OVAL">oval:org.mitre.oval:def:11753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.0" />
        <vers num="9.0.0" edition="rc1" />
        <vers num="9.0.0" edition="rc2" />
        <vers num="9.0.0" edition="rc3" />
        <vers num="9.0.0" edition="rc4" />
        <vers num="9.0.0" edition="rc5" />
        <vers num="9.0.0" edition="rc6" />
        <vers num="9.0.0b1" />
        <vers num="9.0.0b2" />
        <vers num="9.0.0b3" />
        <vers num="9.0.0b4" />
        <vers num="9.0.0b5" />
        <vers num="9.0.1" edition="rc1" />
        <vers num="9.0.1" edition="rc2" />
        <vers num="9.1" />
        <vers num="9.1.0" edition="rc1" />
        <vers num="9.1.0b1" />
        <vers num="9.1.0b2" />
        <vers num="9.1.0b3" />
        <vers num="9.1.1" edition="rc1" />
        <vers num="9.1.1" edition="rc2" />
        <vers num="9.1.1" edition="rc3" />
        <vers num="9.1.1" edition="rc4" />
        <vers num="9.1.1" edition="rc5" />
        <vers num="9.1.1" edition="rc6" />
        <vers num="9.1.1" edition="rc7" />
        <vers num="9.1.2" edition="rc1" />
        <vers num="9.1.3" edition="rc1" />
        <vers num="9.1.3" edition="rc2" />
        <vers num="9.1.3" edition="rc3" />
        <vers num="9.1.3p2" />
        <vers num="9.1.3p3" />
        <vers num="9.2.0" edition="rc1" />
        <vers num="9.2.0" edition="rc10" />
        <vers num="9.2.0" edition="rc2" />
        <vers num="9.2.0" edition="rc3" />
        <vers num="9.2.0" edition="rc4" />
        <vers num="9.2.0" edition="rc5" />
        <vers num="9.2.0" edition="rc6" />
        <vers num="9.2.0" edition="rc7" />
        <vers num="9.2.0" edition="rc8" />
        <vers num="9.2.0" edition="rc9" />
        <vers num="9.2.0a1" />
        <vers num="9.2.0a2" />
        <vers num="9.2.0a3" />
        <vers num="9.2.0b1" />
        <vers num="9.2.0b2" />
        <vers num="9.2.1" edition="rc1" />
        <vers num="9.2.1" edition="rc2" />
        <vers num="9.2.2" edition="p2" />
        <vers num="9.2.2" edition="p3" />
        <vers num="9.2.2" edition="rc1" />
        <vers num="9.2.3" edition="rc1" />
        <vers num="9.2.3" edition="rc2" />
        <vers num="9.2.3" edition="rc3" />
        <vers num="9.2.3" edition="rc4" />
        <vers num="9.2.4" edition="rc2" />
        <vers num="9.2.4" edition="rc3" />
        <vers num="9.2.4" edition="rc4" />
        <vers num="9.2.4" edition="rc5" />
        <vers num="9.2.4" edition="rc6" />
        <vers num="9.2.4" edition="rc7" />
        <vers num="9.2.4" edition="rc8" />
        <vers num="9.2.5" edition="beta2" />
        <vers num="9.2.5" edition="rc1" />
        <vers num="9.2.6" edition="rc1" />
        <vers num="9.2.6b1" />
        <vers num="9.2.6b2" />
        <vers num="9.2.6p1" />
        <vers num="9.2.6p2" />
        <vers num="9.2.7" edition="rc1" />
        <vers num="9.2.7" edition="rc2" />
        <vers num="9.2.7" edition="rc3" />
        <vers num="9.2.7b1" />
        <vers num="9.2.8" />
        <vers num="9.2.8p1" />
        <vers num="9.2.9" edition="rc1" />
        <vers num="9.2.9b1" />
        <vers num="9.3.0" edition="beta2" />
        <vers num="9.3.0" edition="beta3" />
        <vers num="9.3.0" edition="beta4" />
        <vers num="9.3.0" edition="rc1" />
        <vers num="9.3.0" edition="rc2" />
        <vers num="9.3.0" edition="rc3" />
        <vers num="9.3.0" edition="rc4" />
        <vers num="9.3.1" edition="beta2" />
        <vers num="9.3.1" edition="rc1" />
        <vers num="9.3.2" edition="rc1" />
        <vers num="9.3.2b1" />
        <vers num="9.3.2b2" />
        <vers num="9.3.2p1" />
        <vers num="9.3.2p2" />
        <vers num="9.3.3" edition="rc1" />
        <vers num="9.3.3" edition="rc2" />
        <vers num="9.3.3" edition="rc3" />
        <vers num="9.3.3b1" />
        <vers num="9.3.4" />
        <vers num="9.3.4p1" />
        <vers num="9.3.5" edition="rc1" />
        <vers num="9.3.5" edition="rc2" />
        <vers num="9.3.5-p2" />
        <vers num="9.3.5-p2-w1" />
        <vers num="9.3.5-p2-w2" />
        <vers num="9.3.5b1" />
        <vers num="9.3.6" edition="rc1" />
        <vers num="9.3.6b1" />
        <vers num="9.3.6p1" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0" edition="rc2" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.1p1" />
        <vers num="9.4.2" edition="rc1" />
        <vers num="9.4.2" edition="rc2" />
        <vers num="9.4.2b1" />
        <vers num="9.4.2p1" />
        <vers num="9.4.2p2" />
        <vers num="9.4.2p2-w1" />
        <vers num="9.4.2p2-w2" />
        <vers num="9.4.3p1" />
        <vers num="9.4.3p2" />
        <vers num="9.4.3p3" />
        <vers num="9.4.3p4" />
        <vers num="9.5" />
        <vers num="9.5.0" edition="rc1" />
        <vers num="9.5.0a5" />
        <vers num="9.5.0a6" />
        <vers num="9.5.0a7" />
        <vers num="9.5.0b1" />
        <vers num="9.5.0b2" />
        <vers num="9.5.0b3" />
        <vers num="9.5.1" edition="rc1" />
        <vers num="9.5.1" edition="rc2" />
        <vers num="9.5.1b1" />
        <vers num="9.5.1b2" />
        <vers num="9.5.1b3" />
        <vers num="9.5.1p1" />
        <vers num="9.5.1p2" />
        <vers num="9.5.1p3" />
        <vers num="9.5.2" edition="rc1" />
        <vers num="9.5.2b1" />
        <vers num="9.5.2p1" />
        <vers num="9.6.0" edition="p1" />
        <vers num="9.6.0" edition="rc1" />
        <vers num="9.6.0" edition="rc2" />
        <vers num="9.6.0a1" />
        <vers num="9.6.0b1" />
        <vers num="9.6.1" edition="p1" />
        <vers num="9.6.1" edition="p2" />
        <vers num="9.7.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0383" published="2010-01-25" name="CVE-2010-0383" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37901" source="BID">37901</ref>
      <ref url="http://secunia.com/advisories/38198" source="SECUNIA" adv="1">38198</ref>
      <ref url="http://osvdb.org/61977" source="OSVDB">61977</ref>
      <ref url="http://archives.seul.org/or/talk/Jan-2010/msg00165.html" source="MLIST">[or-talk] 20100120 Re: Tor Project infrastructure updates in response to security breach</ref>
      <ref url="http://archives.seul.org/or/talk/Jan-2010/msg00162.html" source="MLIST">[or-talk] 20100120 Tor 0.2.2.7-alpha is out</ref>
      <ref url="http://archives.seul.org/or/talk/Jan-2010/msg00161.html" source="MLIST">[or-talk] 20100120 Tor Project infrastructure updates in response to security breach</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2010/msg00000.html" source="MLIST">[or-announce] 20100121 Tor 0.2.1.22 is released (security fix)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2" />
        <vers num="0.0.2_pre13" />
        <vers num="0.0.2_pre14" />
        <vers num="0.0.2_pre15" />
        <vers num="0.0.2_pre16" />
        <vers num="0.0.2_pre17" />
        <vers num="0.0.2_pre18" />
        <vers num="0.0.2_pre19" />
        <vers num="0.0.2_pre20" />
        <vers num="0.0.2_pre21" />
        <vers num="0.0.2_pre22" />
        <vers num="0.0.2_pre23" />
        <vers num="0.0.2_pre24" />
        <vers num="0.0.2_pre25" />
        <vers num="0.0.2_pre26" />
        <vers num="0.0.2_pre27" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.6.1" />
        <vers num="0.0.6.2" />
        <vers num="0.0.7" />
        <vers num="0.0.7.1" />
        <vers num="0.0.7.2" />
        <vers num="0.0.7.3" />
        <vers num="0.0.8" />
        <vers num="0.0.8.1" />
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.10" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
        <vers num="0.1.0.1" />
        <vers num="0.1.0.10" />
        <vers num="0.1.0.11" />
        <vers num="0.1.0.12" />
        <vers num="0.1.0.13" />
        <vers num="0.1.0.14" />
        <vers num="0.1.0.15" />
        <vers num="0.1.0.16" />
        <vers num="0.1.0.17" />
        <vers num="0.1.0.18" />
        <vers num="0.1.0.19" />
        <vers num="0.1.0.2" />
        <vers num="0.1.0.3" />
        <vers num="0.1.0.4" />
        <vers num="0.1.0.5" />
        <vers num="0.1.0.6" />
        <vers num="0.1.0.7" />
        <vers num="0.1.0.8" />
        <vers num="0.1.0.9" />
        <vers num="0.1.1" />
        <vers num="0.1.1.1" />
        <vers num="0.1.1.10" />
        <vers num="0.1.1.10_alpha" />
        <vers num="0.1.1.11" />
        <vers num="0.1.1.12" />
        <vers num="0.1.1.13" />
        <vers num="0.1.1.14" />
        <vers num="0.1.1.15" />
        <vers num="0.1.1.16" />
        <vers num="0.1.1.17" />
        <vers num="0.1.1.18" />
        <vers num="0.1.1.19" />
        <vers num="0.1.1.1_alpha" />
        <vers num="0.1.1.2" />
        <vers num="0.1.1.20" />
        <vers num="0.1.1.21" />
        <vers num="0.1.1.22" />
        <vers num="0.1.1.23" />
        <vers num="0.1.1.25" />
        <vers num="0.1.1.26" />
        <vers num="0.1.1.2_alpha" />
        <vers num="0.1.1.3" />
        <vers num="0.1.1.3_alpha" />
        <vers num="0.1.1.4" />
        <vers num="0.1.1.4_alpha" />
        <vers num="0.1.1.5" />
        <vers num="0.1.1.5_alpha" />
        <vers num="0.1.1.6" />
        <vers num="0.1.1.6_alpha" />
        <vers num="0.1.1.7" />
        <vers num="0.1.1.7_alpha" />
        <vers num="0.1.1.8" />
        <vers num="0.1.1.8_alpha" />
        <vers num="0.1.1.9" />
        <vers num="0.1.1.9_alpha" />
        <vers num="0.1.2.10" />
        <vers num="0.1.2.11" />
        <vers num="0.1.2.12" />
        <vers num="0.1.2.13" />
        <vers num="0.1.2.14" />
        <vers num="0.1.2.16" />
        <vers num="0.1.2.18" />
        <vers num="0.1.2.19" />
        <vers num="0.1.2.1_alpha-cvs" />
        <vers num="0.1.2.2" />
        <vers num="0.1.2.30" />
        <vers num="0.1.2.4" />
        <vers num="0.1.2.5" edition="alpha" />
        <vers num="0.1.2.7" edition="alpha" />
        <vers num="0.1.2.9" />
        <vers num="0.2.1.1.12" />
        <vers num="0.2.1.1.13" />
        <vers num="0.2.1.1.14" />
        <vers num="0.2.1.1.15" />
        <vers num="0.2.1.1.16" />
        <vers num="0.2.1.1.17" />
        <vers num="0.2.1.1.18" />
        <vers num="0.2.1.1.19" />
        <vers num="0.2.1.1.20" />
        <vers num="0.2.1.1.21" />
        <vers num="0.2.2.1" edition="alpha" />
        <vers num="0.2.2.2" edition="alpha" />
        <vers num="0.2.2.3" edition="alpha" />
        <vers num="0.2.2.4" edition="alpha" />
        <vers num="0.2.2.5" edition="alpha" />
        <vers num="0.2.2.6" edition="alpha" />
        <vers num="0.2.2.7" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0384" published="2010-01-25" name="CVE-2010-0384" modified="2011-04-27" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for local users to discover the identities of clients in opportunistic circumstances by reading log files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://archives.seul.org/or/talk/Jan-2010/msg00162.html" source="MLIST">[or-talk] 20100120 Tor 0.2.2.7-alpha is out</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.2.1" edition="alpha" />
        <vers num="0.2.2.2" edition="alpha" />
        <vers num="0.2.2.3" edition="alpha" />
        <vers num="0.2.2.4" edition="alpha" />
        <vers num="0.2.2.5" edition="alpha" />
        <vers num="0.2.2.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0385" published="2010-01-25" name="CVE-2010-0385" modified="2010-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37901" source="BID">37901</ref>
      <ref url="http://www.osvdb.org/61865" source="OSVDB">61865</ref>
      <ref url="http://secunia.com/advisories/38198" source="SECUNIA" adv="1">38198</ref>
      <ref url="http://archives.seul.org/or/talk/Jan-2010/msg00162.html" source="MLIST">[or-talk] 20100120 Tor 0.2.2.7-alpha is out</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2010/msg00000.html" source="MLIST">[or-announce] 20100121 Tor 0.2.1.22 is released (security fix)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2" />
        <vers num="0.0.2_pre13" />
        <vers num="0.0.2_pre14" />
        <vers num="0.0.2_pre15" />
        <vers num="0.0.2_pre16" />
        <vers num="0.0.2_pre17" />
        <vers num="0.0.2_pre18" />
        <vers num="0.0.2_pre19" />
        <vers num="0.0.2_pre20" />
        <vers num="0.0.2_pre21" />
        <vers num="0.0.2_pre22" />
        <vers num="0.0.2_pre23" />
        <vers num="0.0.2_pre24" />
        <vers num="0.0.2_pre25" />
        <vers num="0.0.2_pre26" />
        <vers num="0.0.2_pre27" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.6.1" />
        <vers num="0.0.6.2" />
        <vers num="0.0.7" />
        <vers num="0.0.7.1" />
        <vers num="0.0.7.2" />
        <vers num="0.0.7.3" />
        <vers num="0.0.8" />
        <vers num="0.0.8.1" />
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.10" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
        <vers num="0.1.0.1" />
        <vers num="0.1.0.10" />
        <vers num="0.1.0.11" />
        <vers num="0.1.0.12" />
        <vers num="0.1.0.13" />
        <vers num="0.1.0.14" />
        <vers num="0.1.0.15" />
        <vers num="0.1.0.16" />
        <vers num="0.1.0.17" />
        <vers num="0.1.0.18" />
        <vers num="0.1.0.19" />
        <vers num="0.1.0.2" />
        <vers num="0.1.0.3" />
        <vers num="0.1.0.4" />
        <vers num="0.1.0.5" />
        <vers num="0.1.0.6" />
        <vers num="0.1.0.7" />
        <vers num="0.1.0.8" />
        <vers num="0.1.0.9" />
        <vers num="0.1.1" />
        <vers num="0.1.1.1" />
        <vers num="0.1.1.10" />
        <vers num="0.1.1.10_alpha" />
        <vers num="0.1.1.11" />
        <vers num="0.1.1.12" />
        <vers num="0.1.1.13" />
        <vers num="0.1.1.14" />
        <vers num="0.1.1.15" />
        <vers num="0.1.1.16" />
        <vers num="0.1.1.17" />
        <vers num="0.1.1.18" />
        <vers num="0.1.1.19" />
        <vers num="0.1.1.1_alpha" />
        <vers num="0.1.1.2" />
        <vers num="0.1.1.20" />
        <vers num="0.1.1.21" />
        <vers num="0.1.1.22" />
        <vers num="0.1.1.23" />
        <vers num="0.1.1.25" />
        <vers num="0.1.1.26" />
        <vers num="0.1.1.2_alpha" />
        <vers num="0.1.1.3" />
        <vers num="0.1.1.3_alpha" />
        <vers num="0.1.1.4" />
        <vers num="0.1.1.4_alpha" />
        <vers num="0.1.1.5" />
        <vers num="0.1.1.5_alpha" />
        <vers num="0.1.1.6" />
        <vers num="0.1.1.6_alpha" />
        <vers num="0.1.1.7" />
        <vers num="0.1.1.7_alpha" />
        <vers num="0.1.1.8" />
        <vers num="0.1.1.8_alpha" />
        <vers num="0.1.1.9" />
        <vers num="0.1.1.9_alpha" />
        <vers num="0.1.2.10" />
        <vers num="0.1.2.11" />
        <vers num="0.1.2.12" />
        <vers num="0.1.2.13" />
        <vers num="0.1.2.14" />
        <vers num="0.1.2.16" />
        <vers num="0.1.2.18" />
        <vers num="0.1.2.19" />
        <vers num="0.1.2.1_alpha-cvs" />
        <vers num="0.1.2.2" />
        <vers num="0.1.2.30" />
        <vers num="0.1.2.4" />
        <vers num="0.1.2.5" edition="alpha" />
        <vers num="0.1.2.7" edition="alpha" />
        <vers num="0.1.2.9" />
        <vers num="0.2.1.1.12" />
        <vers num="0.2.1.1.13" />
        <vers num="0.2.1.1.14" />
        <vers num="0.2.1.1.15" />
        <vers num="0.2.1.1.16" />
        <vers num="0.2.1.1.17" />
        <vers num="0.2.1.1.18" />
        <vers num="0.2.1.1.19" />
        <vers num="0.2.1.1.20" />
        <vers num="0.2.1.1.21" />
        <vers num="0.2.2.1" edition="alpha" />
        <vers num="0.2.2.2" edition="alpha" />
        <vers num="0.2.2.3" edition="alpha" />
        <vers num="0.2.2.4" edition="alpha" />
        <vers num="0.2.2.5" edition="alpha" />
        <vers num="0.2.2.6" edition="alpha" />
        <vers num="0.2.2.7" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0386" published="2010-01-25" name="CVE-2010-0386" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-200942-1


Contributing Factors

This issue can occur in the following releases:

    * Sun Java System Application Server Standard Edition 7 and later updates
    * Sun Java System Application Server Standard Edition 7 2004Q2 and later updates
    * Sun Java System Application Server Platform Edition 7 and later updates</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200942-1" source="SUNALERT" adv="1">200942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_application_server">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":platform" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0387" published="2010-01-25" name="CVE-2010-0387" modified="2010-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55792" source="XF">jsws-digest-header-bo(55792)</ref>
      <ref url="http://www.securityfocus.com/bid/37896" source="BID">37896</ref>
      <ref url="http://securitytracker.com/id?1023488" source="SECTRACK">1023488</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-January/006014.html" source="MLIST">[dailydave] 20100120 Sun Web Server digest auth overflow</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-digest.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70u7-digest.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0388" published="2010-01-25" name="CVE-2010-0388" modified="2010-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55812" source="XF">jsws-webdav-format-string(55812)</ref>
      <ref url="http://www.securityfocus.com/bid/37910" source="BID">37910</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70-webdav.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70-webdav.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0389" published="2010-01-25" name="CVE-2010-0389" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/slices/2000.html

CWE-476 NULL Pointer Dereference</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70-admin.html" source="MISC">http://intevydis.blogspot.com/2010/01/sun-java-system-web-server-70-admin.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_web_server">
        <vers num="7.0" edition="update_6" />
        <vers num="7.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0390" published="2010-01-26" name="CVE-2010-0390" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/.  NOTE: some of these details are obtained from third party information.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html

'CWE-434: Unrestricted Upload of File with Dangerous Type'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11169" source="EXPLOIT-DB">11169</ref>
      <ref url="http://secunia.com/advisories/38018" source="SECUNIA" adv="1">38018</ref>
      <ref url="http://osvdb.org/61808" source="OSVDB">61808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpf1" name="max's_image_uploader">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0391" published="2010-01-26" name="CVE-2010-0391" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Embarcadero Technologies InterBase SMP 2009 9.0.3.437 allow remote attackers to execute arbitrary code via unknown vectors involving crafted packets.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37916" source="BID">37916</ref>
      <ref url="http://secunia.com/advisories/38285" source="SECUNIA" adv="1">38285</ref>
      <ref url="http://osvdb.org/61892" source="OSVDB">61892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="embarcadero" name="interbase_smp_2009">
        <vers num="9.0.3.437" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0392" published="2010-01-26" name="CVE-2010-0392" modified="2011-01-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in vpnconf.exe in TheGreenBow IPSec VPN Client 4.51.001, 4.65.003, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a long OpenScriptAfterUp parameter in a policy (.tgb) file, related to "phase 2."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.thegreenbow.com/download.php?id=1000150" source="CONFIRM" patch="1">http://www.thegreenbow.com/download.php?id=1000150</ref>
      <ref url="http://www.senseofsecurity.com.au/advisories/SOS-10-001" source="MISC" patch="1">http://www.senseofsecurity.com.au/advisories/SOS-10-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55793" source="XF">ipsecvpnclient-tgb-bo(55793)</ref>
      <ref url="http://www.securityfocus.com/bid/40387" source="BID">40387</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509091/100/0/threaded" source="BUGTRAQ">20100121 TheGreenBow VPN Client Local Stack Overflow Vulnerability - Security Advisory - SOS-10-001</ref>
      <ref url="http://secunia.com/advisories/38262" source="SECUNIA" adv="1">38262</ref>
      <ref url="http://osvdb.org/61866" source="OSVDB">61866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thegreenbow" name="ipsec_vpn_client">
        <vers num="4.51.001" />
        <vers num="4.65.003" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0393" published="2010-03-05" name="CVE-2010-0393" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=558460" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=558460</ref>
      <ref url="http://www.ubuntu.com/usn/USN-906-1" source="UBUNTU">USN-906-1</ref>
      <ref url="http://www.securityfocus.com/bid/38524" source="BID">38524</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:073" source="MANDRIVA">MDVSA-2010:073</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:072" source="MANDRIVA">MDVSA-2010:072</ref>
      <ref url="http://www.cups.org/str.php?L3482" source="MISC">http://www.cups.org/str.php?L3482</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.2.2" />
        <vers num="1.3.7" />
        <vers num="1.3.9" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0394" published="2010-02-09" name="CVE-2010-0394" modified="2010-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56105" source="XF">tracgit-command-execution(56105)</ref>
      <ref url="http://www.securityfocus.com/bid/38076" source="BID">38076</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1990" source="DEBIAN">DSA-1990</ref>
      <ref url="http://secunia.com/advisories/38325" source="SECUNIA" adv="1">38325</ref>
      <ref url="http://osvdb.org/62147" source="OSVDB">62147</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567039" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nanosleep" name="trac-git">
        <vers prev="1" num="0.0.20080710" />
        <vers prev="1" num="0.0.20090320" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0395" published="2010-06-09" name="CVE-2010-0395" modified="2010-11-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-287A.html" source="CERT">TA10-287A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1350" source="VUPEN" patch="1" adv="1">ADV-2010-1350</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=574119" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=574119</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2905" source="VUPEN">ADV-2010-2905</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1369" source="VUPEN" adv="1">ADV-2010-1369</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1366" source="VUPEN" adv="1">ADV-2010-1366</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1353" source="VUPEN" adv="1">ADV-2010-1353</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0459.html" source="REDHAT">RHSA-2010:0459</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2010-0395.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2010-0395.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:221" source="MANDRIVA">MDVSA-2010:221</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2055" source="DEBIAN">DSA-2055</ref>
      <ref url="http://ubuntu.com/usn/usn-949-1" source="UBUNTU">USN-949-1</ref>
      <ref url="http://secunia.com/advisories/40107" source="SECUNIA" adv="1">40107</ref>
      <ref url="http://secunia.com/advisories/40104" source="SECUNIA" adv="1">40104</ref>
      <ref url="http://secunia.com/advisories/40084" source="SECUNIA" adv="1">40084</ref>
      <ref url="http://secunia.com/advisories/40070" source="SECUNIA" adv="1">40070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11091" source="OVAL">oval:org.mitre.oval:def:11091</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042534.html" source="FEDORA">FEDORA-2010-9633</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042529.html" source="FEDORA">FEDORA-2010-9628</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042468.html" source="FEDORA">FEDORA-2010-9576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="openoffice.org">
        <vers num="2.0.0" />
        <vers num="2.1.0" />
        <vers num="2.2.0" />
        <vers num="2.3.0" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers prev="1" num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0396" published="2010-03-15" name="CVE-2010-0396" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2010/dsa-2011" source="DEBIAN" patch="1">DSA-2011</ref>
      <ref url="http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29.tar.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/d/dpkg/dpkg_1.14.29.tar.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56887" source="XF">dpkg-dpkgsource-dir-traversal(56887)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0582" source="VUPEN" adv="1">ADV-2010-0582</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="dpkg">
        <vers num="1.10" />
        <vers num="1.10.1" />
        <vers num="1.10.10" />
        <vers num="1.10.11" />
        <vers num="1.10.12" />
        <vers num="1.10.13" />
        <vers num="1.10.14" />
        <vers num="1.10.15" />
        <vers num="1.10.16" />
        <vers num="1.10.17" />
        <vers num="1.10.18" />
        <vers num="1.10.18.1" />
        <vers num="1.10.19" />
        <vers num="1.10.2" />
        <vers num="1.10.20" />
        <vers num="1.10.21" />
        <vers num="1.10.22" />
        <vers num="1.10.23" />
        <vers num="1.10.24" />
        <vers num="1.10.25" />
        <vers num="1.10.26" />
        <vers num="1.10.27" />
        <vers num="1.10.28" />
        <vers num="1.10.3" />
        <vers num="1.10.4" />
        <vers num="1.10.5" />
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.10.9" />
        <vers num="1.13.0" />
        <vers num="1.13.1" />
        <vers num="1.13.10" />
        <vers num="1.13.11" />
        <vers num="1.13.11.1" />
        <vers num="1.13.12" />
        <vers num="1.13.13" />
        <vers num="1.13.14" />
        <vers num="1.13.15" />
        <vers num="1.13.16" />
        <vers num="1.13.17" />
        <vers num="1.13.18" />
        <vers num="1.13.19" />
        <vers num="1.13.2" />
        <vers num="1.13.20" />
        <vers num="1.13.21" />
        <vers num="1.13.22" />
        <vers num="1.13.23" />
        <vers num="1.13.24" />
        <vers num="1.13.25" />
        <vers num="1.13.3" />
        <vers num="1.13.4" />
        <vers num="1.13.5" />
        <vers num="1.13.6" />
        <vers num="1.13.7" />
        <vers num="1.13.8" />
        <vers num="1.13.9" />
        <vers num="1.14.0" />
        <vers num="1.14.1" />
        <vers num="1.14.10" />
        <vers num="1.14.11" />
        <vers num="1.14.12" />
        <vers num="1.14.13" />
        <vers num="1.14.14" />
        <vers num="1.14.15" />
        <vers num="1.14.16" />
        <vers num="1.14.16.1" />
        <vers num="1.14.16.2" />
        <vers num="1.14.16.3" />
        <vers num="1.14.16.4" />
        <vers num="1.14.16.5" />
        <vers num="1.14.16.6" />
        <vers num="1.14.17" />
        <vers num="1.14.18" />
        <vers num="1.14.19" />
        <vers num="1.14.2" />
        <vers num="1.14.20" />
        <vers num="1.14.21" />
        <vers num="1.14.22" />
        <vers num="1.14.23" />
        <vers num="1.14.24" />
        <vers num="1.14.25" />
        <vers num="1.14.26" />
        <vers num="1.14.27" />
        <vers prev="1" num="1.14.28" />
        <vers num="1.14.3" />
        <vers num="1.14.4" />
        <vers num="1.14.5" />
        <vers num="1.14.6" />
        <vers num="1.14.7" />
        <vers num="1.14.8" />
        <vers num="1.14.9" />
        <vers num="1.9.19" />
        <vers num="1.9.20" />
        <vers num="1.9.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0397" published="2010-03-16" name="CVE-2010-0397" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/slices/2000.html

Improper Check for Unusual or Exceptional Conditions CWE-754</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/3081" source="VUPEN">ADV-2010-3081</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0724" source="VUPEN">ADV-2010-0724</ref>
      <ref url="http://www.securityfocus.com/bid/38708" source="BID">38708</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0919.html" source="REDHAT">RHSA-2010:0919</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/12/5" source="MLIST">[oss-security] 20100312 CVE-2010-0397: NULL pointer dereference in PHP's xmlrpc extension</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:068" source="MANDRIVA">MDVSA-2010:068</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://secunia.com/advisories/42410" source="SECUNIA">42410</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573573" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0400" published="2010-04-07" name="CVE-2010-0400" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in lib/user.php in mahara 1.0.4 allows remote attackers to execute arbitrary SQL commands via a username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.debian.org/pool/updates/main/m/mahara/mahara_1.0.4-4+lenny5.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/m/mahara/mahara_1.0.4-4+lenny5.diff.gz</ref>
      <ref url="http://www.securityfocus.com/bid/39253" source="BID">39253</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2030" source="DEBIAN">DSA-2030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0401" published="2010-05-05" name="CVE-2010-0401" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">OpenTTD before 1.0.1 accepts a company password for authentication in response to a request for the server password, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (daemon crash) by sending a company password packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.openttd.org/en/CVE-2010-0401" source="CONFIRM" adv="1">http://security.openttd.org/en/CVE-2010-0401</ref>
      <ref url="http://secunia.com/advisories/39669" source="SECUNIA" adv="1">39669</ref>
      <ref url="http://bugs.openttd.org/task/3754" source="CONFIRM">http://bugs.openttd.org/task/3754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.2.1" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.4.0" />
        <vers num="0.4.0.1" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" edition="rc1" />
        <vers num="0.5.0" edition="rc1" />
        <vers num="0.5.0" edition="rc2" />
        <vers num="0.5.0" edition="rc3" />
        <vers num="0.5.0" edition="rc4" />
        <vers num="0.5.0" edition="rc5" />
        <vers num="0.5.1" edition="rc1" />
        <vers num="0.5.1" edition="rc2" />
        <vers num="0.5.1" edition="rc3" />
        <vers num="0.5.2" edition="rc1" />
        <vers num="0.5.3" edition="rc1" />
        <vers num="0.5.3" edition="rc2" />
        <vers num="0.5.3" edition="rc3" />
        <vers num="0.6.0" edition="beta1" />
        <vers num="0.6.0" edition="beta2" />
        <vers num="0.6.0" edition="beta3" />
        <vers num="0.6.0" edition="beta4" />
        <vers num="0.6.0" edition="beta5" />
        <vers num="0.6.0" edition="rc1" />
        <vers num="0.6.1" edition="rc1" />
        <vers num="0.6.1" edition="rc2" />
        <vers num="0.6.2" edition="rc1" />
        <vers num="0.6.2" edition="rc2" />
        <vers num="0.7.4" />
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0402" published="2010-05-05" name="CVE-2010-0402" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">OpenTTD before 1.0.1 does not properly validate index values of certain items, which allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted in-game command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.openttd.org/en/CVE-2010-0402" source="CONFIRM" adv="1">http://security.openttd.org/en/CVE-2010-0402</ref>
      <ref url="http://secunia.com/advisories/39669" source="SECUNIA" adv="1">39669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.2.1" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.4.0" />
        <vers num="0.4.0.1" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" edition="rc1" />
        <vers num="0.5.0" edition="rc1" />
        <vers num="0.5.0" edition="rc2" />
        <vers num="0.5.0" edition="rc3" />
        <vers num="0.5.0" edition="rc4" />
        <vers num="0.5.0" edition="rc5" />
        <vers num="0.5.1" edition="rc1" />
        <vers num="0.5.1" edition="rc2" />
        <vers num="0.5.1" edition="rc3" />
        <vers num="0.5.2" edition="rc1" />
        <vers num="0.5.3" edition="rc1" />
        <vers num="0.5.3" edition="rc2" />
        <vers num="0.5.3" edition="rc3" />
        <vers num="0.6.0" edition="beta1" />
        <vers num="0.6.0" edition="beta2" />
        <vers num="0.6.0" edition="beta3" />
        <vers num="0.6.0" edition="beta4" />
        <vers num="0.6.0" edition="beta5" />
        <vers num="0.6.0" edition="rc1" />
        <vers num="0.6.1" edition="rc1" />
        <vers num="0.6.1" edition="rc2" />
        <vers num="0.6.2" edition="rc1" />
        <vers num="0.6.2" edition="rc2" />
        <vers num="0.7.4" />
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0403" published="2010-05-19" name="CVE-2010-0403" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1145" source="VUPEN" patch="1" adv="1">ADV-2010-1145</ref>
      <ref url="http://forums.phpgroupware.org/index.php?t=msg&amp;th=98662&amp;start=0&amp;rid=0" source="CONFIRM" patch="1">http://forums.phpgroupware.org/index.php?t=msg&amp;th=98662&amp;start=0&amp;rid=0</ref>
      <ref url="http://download.phpgroupware.org/" source="CONFIRM" patch="1" adv="1">http://download.phpgroupware.org/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58657" source="XF">phpgroupware-about-file-include(58657)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1146" source="VUPEN" adv="1">ADV-2010-1146</ref>
      <ref url="http://www.securityfocus.com/bid/40167" source="BID">40167</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511299/100/0/threaded" source="BUGTRAQ">20100514 phpGroupWare SQL Injections and Local File Inclusion Vulnerabilities (CVE-2010-0403 and CVE-2010-0404)</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2046" source="DEBIAN">DSA-2046</ref>
      <ref url="http://secunia.com/advisories/39731" source="SECUNIA" adv="1">39731</ref>
      <ref url="http://secunia.com/advisories/39665" source="SECUNIA" adv="1">39665</ref>
      <ref url="http://lists.gnu.org/archive/html/phpgroupware-users/2010-05/msg00004.html" source="MLIST">[phpgroupware-users] 20100512 Phpgroupware security release 0.9.16.016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.16" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.001" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16.003" />
        <vers num="0.9.16.005" />
        <vers num="0.9.16.010" />
        <vers num="0.9.16.011" />
        <vers num="0.9.16.012" />
        <vers num="0.9.16.014" />
        <vers prev="1" num="0.9.16.015" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0404" published="2010-05-19" name="CVE-2010-0404" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.gnu.org/archive/html/phpgroupware-users/2010-05/msg00004.html" source="MLIST" patch="1">[phpgroupware-users] 20100512 Phpgroupware security release 0.9.16.016</ref>
      <ref url="http://forums.phpgroupware.org/index.php?t=msg&amp;th=98662&amp;start=0&amp;rid=0" source="CONFIRM" patch="1">http://forums.phpgroupware.org/index.php?t=msg&amp;th=98662&amp;start=0&amp;rid=0</ref>
      <ref url="http://download.phpgroupware.org/" source="CONFIRM" patch="1" adv="1">http://download.phpgroupware.org/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1146" source="VUPEN" adv="1">ADV-2010-1146</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1145" source="VUPEN" adv="1">ADV-2010-1145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511299/100/0/threaded" source="BUGTRAQ">20100514 phpGroupWare SQL Injections and Local File Inclusion Vulnerabilities (CVE-2010-0403 and CVE-2010-0404)</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2046" source="DEBIAN">DSA-2046</ref>
      <ref url="http://secunia.com/advisories/39731" source="SECUNIA" adv="1">39731</ref>
      <ref url="http://secunia.com/advisories/39665" source="SECUNIA" adv="1">39665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpgroupware" name="phpgroupware">
        <vers num="0.9.16" />
        <vers num="0.9.16.000" />
        <vers num="0.9.16.001" />
        <vers num="0.9.16.002" />
        <vers num="0.9.16.003" />
        <vers num="0.9.16.005" />
        <vers num="0.9.16.010" />
        <vers num="0.9.16.011" />
        <vers num="0.9.16.012" />
        <vers num="0.9.16.014" />
        <vers prev="1" num="0.9.16.015" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0405" published="2010-09-28" name="CVE-2010-0405" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2231" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2231</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2230" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2230</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=627882" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=627882</ref>
      <ref url="http://xorl.wordpress.com/2010/09/21/cve-2010-0405-bzip2-integer-overflow/" source="CONFIRM">http://xorl.wordpress.com/2010/09/21/cve-2010-0405-bzip2-integer-overflow/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3127" source="VUPEN">ADV-2010-3127</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3126" source="VUPEN">ADV-2010-3126</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3073" source="VUPEN">ADV-2010-3073</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3052" source="VUPEN">ADV-2010-3052</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3043" source="VUPEN">ADV-2010-3043</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2455" source="VUPEN">ADV-2010-2455</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0019.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0019.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-986-3" source="UBUNTU">USN-986-3</ref>
      <ref url="http://www.ubuntu.com/usn/USN-986-2" source="UBUNTU">USN-986-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-986-1" source="UBUNTU">USN-986-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515055/100/0/threaded" source="BUGTRAQ">20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0858.html" source="REDHAT">RHSA-2010:0858</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0703.html" source="REDHAT">RHSA-2010:0703</ref>
      <ref url="http://www.bzip.org/" source="CONFIRM">http://www.bzip.org/</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://secunia.com/advisories/42530" source="SECUNIA">42530</ref>
      <ref url="http://secunia.com/advisories/42529" source="SECUNIA">42529</ref>
      <ref url="http://secunia.com/advisories/42405" source="SECUNIA">42405</ref>
      <ref url="http://secunia.com/advisories/42404" source="SECUNIA">42404</ref>
      <ref url="http://secunia.com/advisories/42350" source="SECUNIA">42350</ref>
      <ref url="http://secunia.com/advisories/41505" source="SECUNIA">41505</ref>
      <ref url="http://secunia.com/advisories/41452" source="SECUNIA" adv="1">41452</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=128506868510655&amp;w=2" source="MLIST">[oss-security] 20100921 bzip2 CVE-2010-0405 integer overflow</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051366.html" source="FEDORA">FEDORA-2010-1512</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051278.html" source="FEDORA">FEDORA-2010-17439</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.3" source="CONFIRM">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.3</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_0405_integer_overflow" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_0405_integer_overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bzip" name="bzip2">
        <vers num="0.9" />
        <vers num="0.9.0" />
        <vers num="0.9.0a" />
        <vers num="0.9.0b" />
        <vers num="0.9.0c" />
        <vers num="0.9.5_a" />
        <vers num="0.9.5_b" />
        <vers num="0.9.5_c" />
        <vers num="0.9.5_d" />
        <vers num="0.9.5a" />
        <vers num="0.9.5b" />
        <vers num="0.9.5c" />
        <vers num="0.9.5d" />
        <vers num="0.9_a" />
        <vers num="0.9_b" />
        <vers num="0.9_c" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers prev="1" num="1.0.5" />
      </prod>
      <prod vendor="libzip2" name="libzip2">
        <vers prev="1" num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0406" published="2010-05-05" name="CVE-2010-0406" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">OpenTTD before 1.0.1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and daemon crash) by performing incomplete downloads of the map.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.openttd.org/en/CVE-2010-0406" source="CONFIRM" adv="1">http://security.openttd.org/en/CVE-2010-0406</ref>
      <ref url="http://secunia.com/advisories/39669" source="SECUNIA" adv="1">39669</ref>
      <ref url="http://bugs.openttd.org/task/3785" source="CONFIRM" adv="1">http://bugs.openttd.org/task/3785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openttd" name="openttd">
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.2.1" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.4.0" />
        <vers num="0.4.0.1" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" edition="rc1" />
        <vers num="0.5.0" edition="rc1" />
        <vers num="0.5.0" edition="rc2" />
        <vers num="0.5.0" edition="rc3" />
        <vers num="0.5.0" edition="rc4" />
        <vers num="0.5.0" edition="rc5" />
        <vers num="0.5.1" edition="rc1" />
        <vers num="0.5.1" edition="rc2" />
        <vers num="0.5.1" edition="rc3" />
        <vers num="0.5.2" edition="rc1" />
        <vers num="0.5.3" edition="rc1" />
        <vers num="0.5.3" edition="rc2" />
        <vers num="0.5.3" edition="rc3" />
        <vers num="0.6.0" edition="beta1" />
        <vers num="0.6.0" edition="beta2" />
        <vers num="0.6.0" edition="beta3" />
        <vers num="0.6.0" edition="beta4" />
        <vers num="0.6.0" edition="beta5" />
        <vers num="0.6.0" edition="rc1" />
        <vers num="0.6.1" edition="rc1" />
        <vers num="0.6.1" edition="rc2" />
        <vers num="0.6.2" edition="rc1" />
        <vers num="0.6.2" edition="rc2" />
        <vers num="0.7.4" />
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0407" published="2010-06-18" name="CVE-2010-0407" modified="2010-09-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=596426" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=596426</ref>
      <ref url="http://www.securityfocus.com/bid/40758" source="BID" patch="1">40758</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2059" source="DEBIAN" patch="1">DSA-2059</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1508" source="VUPEN" adv="1">ADV-2010-1508</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1427" source="VUPEN" adv="1">ADV-2010-1427</ref>
      <ref url="http://svn.debian.org/wsvn/pcsclite/?sc=1&amp;rev=4208" source="CONFIRM">http://svn.debian.org/wsvn/pcsclite/?sc=1&amp;rev=4208</ref>
      <ref url="http://secunia.com/advisories/40239" source="SECUNIA" adv="1">40239</ref>
      <ref url="http://secunia.com/advisories/40140" source="SECUNIA" adv="1">40140</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042921.html" source="FEDORA">FEDORA-2010-10014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042900.html" source="FEDORA">FEDORA-2010-9995</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044124.html" source="FEDORA">FEDORA-2010-10764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="muscle" name="pcsc-lite">
        <vers num="1.1.2" edition="beta2" />
        <vers num="1.1.2" edition="beta3" />
        <vers num="1.1.2" edition="beta4" />
        <vers num="1.1.2" edition="beta5" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.0" edition="rc2" />
        <vers num="1.2.0" edition="rc3" />
        <vers num="1.2.9" edition="beta1" />
        <vers num="1.2.9" edition="beta10" />
        <vers num="1.2.9" edition="beta2" />
        <vers num="1.2.9" edition="beta3" />
        <vers num="1.2.9" edition="beta4" />
        <vers num="1.2.9" edition="beta5" />
        <vers num="1.2.9" edition="beta6" />
        <vers num="1.2.9" edition="beta7" />
        <vers num="1.2.9" edition="beta8" />
        <vers num="1.2.9" edition="beta9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.100" />
        <vers num="1.4.101" />
        <vers num="1.4.102" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.99" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers prev="1" num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0408" published="2010-03-05" name="CVE-2010-0408" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/703.html

CWE-703: Failure to Handle Exceptional Conditions</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://httpd.apache.org/security/vulnerabilities_22.html

Affects: 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/modules/proxy/mod_proxy_ajp.c?r1=917876&amp;r2=917875&amp;pathrev=917876" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/modules/proxy/mod_proxy_ajp.c?r1=917876&amp;r2=917875&amp;pathrev=917876</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM" patch="1" adv="1">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=569905" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=569905</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1411" source="VUPEN">ADV-2010-1411</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1057" source="VUPEN">ADV-2010-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0994" source="VUPEN">ADV-2010-0994</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0911" source="VUPEN">ADV-2010-0911</ref>
      <ref url="http://www.securityfocus.com/bid/38491" source="BID">38491</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0168.html" source="REDHAT">RHSA-2010:0168</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:053" source="MANDRIVA">MDVSA-2010:053</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2035" source="DEBIAN">DSA-2035</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829" source="AIXAPAR">PM15829</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" source="AIXAPAR">PM12247</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939" source="AIXAPAR">PM08939</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=917876" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=917876</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/40096" source="SECUNIA">40096</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39632" source="SECUNIA">39632</ref>
      <ref url="http://secunia.com/advisories/39628" source="SECUNIA">39628</ref>
      <ref url="http://secunia.com/advisories/39501" source="SECUNIA">39501</ref>
      <ref url="http://secunia.com/advisories/39100" source="SECUNIA">39100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9935" source="OVAL">oval:org.mitre.oval:def:9935</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8619" source="OVAL">oval:org.mitre.oval:def:8619</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html" source="FEDORA">FEDORA-2010-6131</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html" source="FEDORA">FEDORA-2010-5942</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2" />
        <vers num="2.2.0" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0409" published="2010-02-08" name="CVE-2010-0409" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ftp.gnome.org/pub/GNOME/sources/gmime/2.4/gmime-2.4.14-2.4.15.diff.gz" source="CONFIRM" patch="1">http://ftp.gnome.org/pub/GNOME/sources/gmime/2.4/gmime-2.4.14-2.4.15.diff.gz</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=561457" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=561457</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/03/4" source="MLIST">[oss-security] 20100203 Re: CVE Request -- GMime-2.4.15</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/03/2" source="MLIST">[oss-security] 20100203 CVE Request -- GMime-2.4.15</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38459" source="SECUNIA">38459</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://ftp.gnome.org/pub/GNOME/sources/gmime/2.4/gmime-2.4.15.changes" source="CONFIRM">http://ftp.gnome.org/pub/GNOME/sources/gmime/2.4/gmime-2.4.15.changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gmime">
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.13" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0410" published="2010-02-22" name="CVE-2010-0410" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.8" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.8</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=561682" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=561682</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.securityfocus.com/bid/38058" source="BID">38058</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0398.html" source="REDHAT">RHSA-2010:0398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/03/3" source="MLIST">[oss-security] 20100203 Re: CVE request: kernel OOM/crash in drivers/connector</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/03/1" source="MLIST">[oss-security] 20100203 CVE request: kernel OOM/crash in drivers/connector</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2010_23_kernel.html" source="SUSE">SUSE-SA:2010:023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:088" source="MANDRIVA">MDVSA-2010:088</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100088287" source="CONFIRM">http://support.avaya.com/css/P8/documents/100088287</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39742" source="SECUNIA">39742</ref>
      <ref url="http://secunia.com/advisories/39649" source="SECUNIA">39649</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://secunia.com/advisories/38557" source="SECUNIA">38557</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10903" source="OVAL">oval:org.mitre.oval:def:10903</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE">SUSE-SA:2010:019</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE">SUSE-SA:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html" source="FEDORA">FEDORA-2010-1787</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035070.html" source="FEDORA">FEDORA-2010-1804</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f98bfbd78c37c5946cc53089da32a5f741efdeb7" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=f98bfbd78c37c5946cc53089da32a5f741efdeb7</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers prev="1" num="2.6.32.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0411" published="2010-02-08" name="CVE-2010-0411" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559719" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559719</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.securityfocus.com/bid/38120" source="BID">38120</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0125.html" source="REDHAT">RHSA-2010:0125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0124.html" source="REDHAT">RHSA-2010:0124</ref>
      <ref url="http://sourceware.org/git/gitweb.cgi?p=systemtap.git;a=commit;h=a2d399c87a642190f08ede63dc6fc434a5a8363a" source="CONFIRM">http://sourceware.org/git/gitweb.cgi?p=systemtap.git;a=commit;h=a2d399c87a642190f08ede63dc6fc434a5a8363a</ref>
      <ref url="http://sourceware.org/bugzilla/show_bug.cgi?id=11234" source="CONFIRM">http://sourceware.org/bugzilla/show_bug.cgi?id=11234</ref>
      <ref url="http://securitytracker.com/id?1023664" source="SECTRACK">1023664</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/38817" source="SECUNIA">38817</ref>
      <ref url="http://secunia.com/advisories/38765" source="SECUNIA">38765</ref>
      <ref url="http://secunia.com/advisories/38680" source="SECUNIA">38680</ref>
      <ref url="http://secunia.com/advisories/38426" source="SECUNIA" adv="1">38426</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9675" source="OVAL">oval:org.mitre.oval:def:9675</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126530657715364&amp;w=2" source="MLIST">[oss-security] 20100204 systemtap DoS issue (CVE-2010-0411)</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035261.html" source="FEDORA">FEDORA-2010-1720</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035201.html" source="FEDORA">FEDORA-2010-1373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemtap" name="systemtap">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0412" published="2010-02-24" name="CVE-2010-0412" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">stap-server in SystemTap 1.1 does not properly restrict the value of the -B (aka BUILD) option, which allows attackers to have an unspecified impact via vectors associated with executing the make program, a different vulnerability than CVE-2009-4273.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56611" source="XF">systemtap-stapserver-unspecified(56611)</ref>
      <ref url="http://www.securityfocus.com/bid/38316" source="BID">38316</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/scm-commits/2010-February/394714.html" source="MLIST">[scm-commits] 20100215 rpms/systemtap/devel systemtap-1.1-tighten-server-params.patch, NONE, 1.1 systemtap.spec, 1.59, 1.60</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035261.html" source="FEDORA">FEDORA-2010-1720</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035201.html" source="FEDORA">FEDORA-2010-1373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemtap" name="systemtap">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0414" published="2010-02-11" name="CVE-2010-0414" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=562217" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=562217</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=609337" source="CONFIRM">https://bugzilla.gnome.org/show_bug.cgi?id=609337</ref>
      <ref url="http://www.ubuntu.com/usn/USN-898-1" source="UBUNTU">USN-898-1</ref>
      <ref url="http://www.securityfocus.com/bid/38149" source="BID">38149</ref>
      <ref url="http://www.osvdb.org/62219" source="OSVDB">62219</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:040" source="MANDRIVA">MDVSA-2010:040</ref>
      <ref url="http://secunia.com/advisories/38534" source="SECUNIA" adv="1">38534</ref>
      <ref url="http://secunia.com/advisories/38532" source="SECUNIA">38532</ref>
      <ref url="http://secunia.com/advisories/38468" source="SECUNIA" adv="1">38468</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034904.html" source="FEDORA">FEDORA-2010-1556</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=dcca89b7ab6e1220815af38da246434b2e13fd9f" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=dcca89b7ab6e1220815af38da246434b2e13fd9f</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=a5f66339be6719c2b8fc478a1d5fc6545297d950" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=a5f66339be6719c2b8fc478a1d5fc6545297d950</ref>
      <ref url="http://ftp.gnome.org/pub/GNOME/sources/gnome-screensaver/2.28/gnome-screensaver-2.28.2.news" source="CONFIRM">http://ftp.gnome.org/pub/GNOME/sources/gnome-screensaver/2.28/gnome-screensaver-2.28.2.news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="screensaver">
        <vers num="2.13" />
        <vers num="2.20" />
        <vers num="2.20.0" />
        <vers num="2.26.1" />
        <vers num="2.28.0" />
        <vers prev="1" num="2.28.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0415" published="2010-02-17" name="CVE-2010-0415" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=562582" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=562582</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.securityfocus.com/bid/38144" source="BID">38144</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0147.html" source="REDHAT">RHSA-2010:0147</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/08/2" source="MLIST">[oss-security] 20100208 Re: CVE request: information leak / potential crash in sys_move_pages</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/07/2" source="MLIST">[oss-security] 20100207 Re: CVE request: information leak / potential crash in sys_move_pages</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/07/1" source="MLIST">[oss-security] 20100207 CVE request: information leak / potential crash in sys_move_pages</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:066" source="MANDRIVA">MDVSA-2010:066</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1996" source="DEBIAN">DSA-1996</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://secunia.com/advisories/38557" source="SECUNIA">38557</ref>
      <ref url="http://secunia.com/advisories/38492" source="SECUNIA">38492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9399" source="OVAL">oval:org.mitre.oval:def:9399</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE">SUSE-SA:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035159.html" source="FEDORA">FEDORA-2010-1787</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035070.html" source="FEDORA">FEDORA-2010-1804</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6f5a55f1a6c5abee15a0e878e5c74d9f1569b8b0" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6f5a55f1a6c5abee15a0e878e5c74d9f1569b8b0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers prev="1" num="2.6.33" edition="rc4" />
        <vers prev="1" num="2.6.33" edition="rc5" />
        <vers prev="1" num="2.6.33" edition="rc6" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0416" published="2010-02-18" name="CVE-2010-0416" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1" source="CONFIRM">https://helixcommunity.org/viewcvs/common/util/hxurl.cpp?view=log#rev1.24.4.1.4.1</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=561856" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=561856</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0094.html" source="REDHAT">RHSA-2010:0094</ref>
      <ref url="http://secunia.com/advisories/38450" source="SECUNIA">38450</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10847" source="OVAL">oval:org.mitre.oval:def:10847</ref>
      <ref url="http://lists.helixcommunity.org/pipermail/common-cvs/2007-July/014956.html" source="MLIST">[common-cvs] 20070703 util hxurl.cpp,1.24.4.1,1.24.4.1.4.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0417" published="2010-02-18" name="CVE-2010-0417" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://helixcommunity.org/viewcvs/common/util/rlstate.cpp?view=log#rev1.10" source="CONFIRM">https://helixcommunity.org/viewcvs/common/util/rlstate.cpp?view=log#rev1.10</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=561860" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=561860</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0094.html" source="REDHAT">RHSA-2010:0094</ref>
      <ref url="http://secunia.com/advisories/38450" source="SECUNIA">38450</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11364" source="OVAL">oval:org.mitre.oval:def:11364</ref>
      <ref url="http://lists.helixcommunity.org/pipermail/common-cvs/2008-January/015484.html" source="MLIST">[common-cvs] 20080114 util rlstate.cpp,1.9,1.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num="1.0.6" />
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0418" published="2010-03-10" name="CVE-2010-0418" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.chumby.com/pages/release10mar" source="CONFIRM" patch="1" adv="1">http://www.chumby.com/pages/release10mar</ref>
      <ref url="http://www.awe.com/mark/blog/20100305.html" source="MISC" patch="1">http://www.awe.com/mark/blog/20100305.html</ref>
      <ref url="http://secunia.com/advisories/38972" source="SECUNIA">38972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chumby" name="chumby_classic">
        <vers num="0.9" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers prev="1" num="1.7.1" />
      </prod>
      <prod vendor="chumby" name="chumby_one">
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0419" published="2010-03-05" name="CVE-2010-0419" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=563463" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=563463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56662" source="XF">kernel-selectors-privilege-escalation(56662)</ref>
      <ref url="http://www.securityfocus.com/bid/38467" source="BID">38467</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0126.html" source="REDHAT">RHSA-2010:0126</ref>
      <ref url="http://securitytracker.com/id?1023663" source="SECTRACK">1023663</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10139" source="OVAL">oval:org.mitre.oval:def:10139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kvm_qumranet" name="kvm">
        <vers num="83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0420" published="2010-02-24" name="CVE-2010-0420" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing &lt;br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0413" source="VUPEN" patch="1" adv="1">ADV-2010-0413</ref>
      <ref url="http://developer.pidgin.im/wiki/ChangeLog" source="CONFIRM" patch="1">http://developer.pidgin.im/wiki/ChangeLog</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0115.html" source="REDHAT">RHSA-2010:0115</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=565786" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=565786</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56399" source="XF">pidgin-xmpp-nickname-dos(56399)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1020" source="VUPEN">ADV-2010-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0914" source="VUPEN">ADV-2010-0914</ref>
      <ref url="http://www.ubuntu.com/usn/USN-902-1" source="UBUNTU">USN-902-1</ref>
      <ref url="http://www.securityfocus.com/bid/38294" source="BID">38294</ref>
      <ref url="http://www.osvdb.org/62439" source="OSVDB">62439</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:085" source="MANDRIVA">MDVSA-2010:085</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:041" source="MANDRIVA">MDVSA-2010:041</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2038" source="DEBIAN">DSA-2038</ref>
      <ref url="http://secunia.com/advisories/39509" source="SECUNIA">39509</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38712" source="SECUNIA" adv="1">38712</ref>
      <ref url="http://secunia.com/advisories/38658" source="SECUNIA" adv="1">38658</ref>
      <ref url="http://secunia.com/advisories/38640" source="SECUNIA" adv="1">38640</ref>
      <ref url="http://secunia.com/advisories/38563" source="SECUNIA" adv="1">38563</ref>
      <ref url="http://pidgin.im/news/security/?id=44" source="CONFIRM" adv="1">http://pidgin.im/news/security/?id=44</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11485" source="OVAL">oval:org.mitre.oval:def:11485</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.html" source="FEDORA">FEDORA-2010-1383</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.html" source="FEDORA">FEDORA-2010-1934</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.html" source="FEDORA">FEDORA-2010-1279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0421" published="2010-03-18" name="CVE-2010-0421" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ftp.gnome.org/pub/GNOME/sources/pango/1.27/pango-1.27.1.tar.bz2" source="CONFIRM" patch="1">http://ftp.gnome.org/pub/GNOME/sources/pango/1.27/pango-1.27.1.tar.bz2</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=555831" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=555831</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1552" source="VUPEN">ADV-2010-1552</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0661" source="VUPEN">ADV-2010-0661</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0627" source="VUPEN">ADV-2010-0627</ref>
      <ref url="http://www.securityfocus.com/bid/38760" source="BID">38760</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0140.html" source="REDHAT">RHSA-2010:0140</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:121" source="MANDRIVA">MDVSA-2010:121</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2019" source="DEBIAN">DSA-2019</ref>
      <ref url="http://securitytracker.com/id?1023711" source="SECTRACK">1023711</ref>
      <ref url="http://secunia.com/advisories/39041" source="SECUNIA">39041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9417" source="OVAL">oval:org.mitre.oval:def:9417</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html" source="SUSE">SUSE-SR:2010:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pango" name="pango">
        <vers prev="1" num="1.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0422" published="2010-02-24" name="CVE-2010-0422" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:C/A:N)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting monitors multiple times, a related issue to CVE-2010-0414.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=564464" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=564464</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=609789" source="CONFIRM">https://bugzilla.gnome.org/show_bug.cgi?id=609789</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56364" source="XF">gnome-screensaver-monitor-sec-bypass(56364)</ref>
      <ref url="http://www.securityfocus.com/bid/38248" source="BID">38248</ref>
      <ref url="http://secunia.com/advisories/38583" source="SECUNIA" adv="1">38583</ref>
      <ref url="http://secunia.com/advisories/38565" source="SECUNIA" adv="1">38565</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126601292400764&amp;w=2" source="MLIST">[oss-security] 20100212 Re: gnome-screensaver vulnerability (CVE-2010-0414)</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035115.html" source="FEDORA">FEDORA-2010-1855</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=f93a22c175090cf02e80bc3ee676b53f1251f685" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=f93a22c175090cf02e80bc3ee676b53f1251f685</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=d4dcbd65a2df3c093c4e3a74bbbc75383eb9eadb" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=d4dcbd65a2df3c093c4e3a74bbbc75383eb9eadb</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=271ae93d7b140b8ba40d77f9e4ce894e5fd1b554" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?id=271ae93d7b140b8ba40d77f9e4ce894e5fd1b554</ref>
      <ref url="http://ftp.gnome.org/pub/GNOME/sources/gnome-screensaver/2.28/gnome-screensaver-2.28.3.news" source="CONFIRM">http://ftp.gnome.org/pub/GNOME/sources/gnome-screensaver/2.28/gnome-screensaver-2.28.3.news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="screensaver">
        <vers num="2.28.0" />
        <vers num="2.28.1" />
        <vers num="2.28.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0423" published="2010-02-24" name="CVE-2010-0423" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0413" source="VUPEN" patch="1" adv="1">ADV-2010-0413</ref>
      <ref url="http://pidgin.im/news/security/?id=45" source="CONFIRM" patch="1" adv="1">http://pidgin.im/news/security/?id=45</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0115.html" source="REDHAT">RHSA-2010:0115</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=565792" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=565792</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56394" source="XF">pidgin-smileys-dos(56394)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1020" source="VUPEN">ADV-2010-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0914" source="VUPEN">ADV-2010-0914</ref>
      <ref url="http://www.ubuntu.com/usn/USN-902-1" source="UBUNTU">USN-902-1</ref>
      <ref url="http://www.securityfocus.com/bid/38294" source="BID">38294</ref>
      <ref url="http://www.osvdb.org/62440" source="OSVDB">62440</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:085" source="MANDRIVA">MDVSA-2010:085</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:041" source="MANDRIVA">MDVSA-2010:041</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2038" source="DEBIAN">DSA-2038</ref>
      <ref url="http://secunia.com/advisories/39509" source="SECUNIA">39509</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38712" source="SECUNIA" adv="1">38712</ref>
      <ref url="http://secunia.com/advisories/38658" source="SECUNIA" adv="1">38658</ref>
      <ref url="http://secunia.com/advisories/38640" source="SECUNIA" adv="1">38640</ref>
      <ref url="http://secunia.com/advisories/38563" source="SECUNIA" adv="1">38563</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9842" source="OVAL">oval:org.mitre.oval:def:9842</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035409.html" source="FEDORA">FEDORA-2010-1383</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035347.html" source="FEDORA">FEDORA-2010-1934</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035332.html" source="FEDORA">FEDORA-2010-1279</ref>
      <ref url="http://developer.pidgin.im/wiki/ChangeLog" source="CONFIRM">http://developer.pidgin.im/wiki/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0424" published="2010-02-25" name="CVE-2010-0424" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=565809" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=565809</ref>
      <ref url="http://www.securityfocus.com/bid/38391" source="BID">38391</ref>
      <ref url="http://secunia.com/advisories/38741" source="SECUNIA" adv="1">38741</ref>
      <ref url="http://secunia.com/advisories/38700" source="SECUNIA" adv="1">38700</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035762.html" source="FEDORA">FEDORA-2010-2751</ref>
      <ref url="http://git.fedorahosted.org/git/cronie.git?p=cronie.git;a=commit;h=9e4a8fa5f9171fb724981f53879c9b20264aeb61" source="CONFIRM" adv="1">http://git.fedorahosted.org/git/cronie.git?p=cronie.git;a=commit;h=9e4a8fa5f9171fb724981f53879c9b20264aeb61</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedorahosted" name="cronie">
        <vers prev="1" num="1.4.3" />
      </prod>
      <prod vendor="paul_vixie" name="vixie_cron">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0425" published="2010-03-05" name="CVE-2010-0425" modified="2010-12-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/280613" source="CERT-VN">VU#280613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56624" source="XF">apache-http-modisapi-ocp-unspecified(56624)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0994" source="VUPEN" adv="1">ADV-2010-0994</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0634" source="VUPEN" adv="1">ADV-2010-0634</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0014.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0014.html</ref>
      <ref url="http://www.senseofsecurity.com.au/advisories/SOS-10-002" source="MISC">http://www.senseofsecurity.com.au/advisories/SOS-10-002</ref>
      <ref url="http://www.securitytracker.com/id?1023701" source="SECTRACK">1023701</ref>
      <ref url="http://www.securityfocus.com/bid/38494" source="BID">38494</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" source="AIXAPAR">PM12247</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447" source="AIXAPAR">PM09447</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=917870" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=917870</ref>
      <ref url="http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&amp;r2=917869&amp;pathrev=917870" source="CONFIRM">http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&amp;r2=917869&amp;pathrev=917870</ref>
      <ref url="http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&amp;r2=917869&amp;pathrev=917870" source="CONFIRM">http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&amp;r2=917869&amp;pathrev=917870</ref>
      <ref url="http://secunia.com/advisories/39628" source="SECUNIA" adv="1">39628</ref>
      <ref url="http://secunia.com/advisories/38978" source="SECUNIA" adv="1">38978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8439" source="OVAL">oval:org.mitre.oval:def:8439</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000105.html" source="MLIST">[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_20.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_20.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.0.28" edition="beta" />
        <vers num="2.0.32" edition="beta" />
        <vers num="2.0.34" edition="beta" />
        <vers num="2.0.35" />
        <vers num="2.0.36" />
        <vers num="2.0.37" />
        <vers num="2.0.38" />
        <vers num="2.0.39" />
        <vers num="2.0.40" />
        <vers num="2.0.41" />
        <vers num="2.0.42" />
        <vers num="2.0.43" />
        <vers num="2.0.44" />
        <vers num="2.0.45" />
        <vers num="2.0.46" />
        <vers num="2.0.47" />
        <vers num="2.0.48" />
        <vers num="2.0.49" />
        <vers num="2.0.50" />
        <vers num="2.0.51" />
        <vers num="2.0.52" />
        <vers num="2.0.53" />
        <vers num="2.0.54" />
        <vers num="2.0.55" />
        <vers num="2.0.56" />
        <vers num="2.0.57" />
        <vers num="2.0.58" />
        <vers num="2.0.59" />
        <vers num="2.0.60" />
        <vers num="2.0.61" />
        <vers num="2.0.63" />
        <vers num="2.0.9" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0426" published="2010-02-24" name="CVE-2010-0426" modified="2011-01-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.sudo.ws/sudo/stable.html" source="CONFIRM" patch="1">http://www.sudo.ws/sudo/stable.html</ref>
      <ref url="http://www.securityfocus.com/bid/38362" source="BID" patch="1">38362</ref>
      <ref url="ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz" source="CONFIRM" patch="1">ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0949" source="VUPEN">ADV-2010-0949</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0450" source="VUPEN" adv="1">ADV-2010-0450</ref>
      <ref url="http://www.ubuntu.com/usn/USN-905-1" source="UBUNTU">USN-905-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514489/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0075-1 sudo</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:049" source="MANDRIVA">MDVSA-2010:049</ref>
      <ref url="http://www.linuxquestions.org/questions/linux-security-4/the-use-of-sudoedit-command-question-785442/" source="MISC">http://www.linuxquestions.org/questions/linux-security-4/the-use-of-sudoedit-command-question-785442/</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-201003-01.xml" source="GENTOO">GLSA-201003-01</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2006" source="DEBIAN">DSA-2006</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2010-0075" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2010-0075</ref>
      <ref url="http://sudo.ws/repos/sudo/rev/f86e1b56d074" source="CONFIRM">http://sudo.ws/repos/sudo/rev/f86e1b56d074</ref>
      <ref url="http://sudo.ws/repos/sudo/rev/88f3181692fe" source="CONFIRM">http://sudo.ws/repos/sudo/rev/88f3181692fe</ref>
      <ref url="http://sudo.ws/bugs/show_bug.cgi?id=389" source="CONFIRM">http://sudo.ws/bugs/show_bug.cgi?id=389</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.577019" source="SLACKWARE">SSA:2010-110-01</ref>
      <ref url="http://securitytracker.com/id?1023658" source="SECTRACK">1023658</ref>
      <ref url="http://secunia.com/advisories/39399" source="SECUNIA">39399</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38803" source="SECUNIA">38803</ref>
      <ref url="http://secunia.com/advisories/38795" source="SECUNIA">38795</ref>
      <ref url="http://secunia.com/advisories/38762" source="SECUNIA">38762</ref>
      <ref url="http://secunia.com/advisories/38659" source="SECUNIA" adv="1">38659</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7238" source="OVAL">oval:org.mitre.oval:def:7238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10814" source="OVAL">oval:org.mitre.oval:def:10814</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040588.html" source="FEDORA">FEDORA-2010-6749</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040578.html" source="FEDORA">FEDORA-2010-6701</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=570737" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=570737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.7_p5" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p12" />
        <vers num="1.6.8_p2" />
        <vers num="1.6.8_p5" />
        <vers num="1.6.8_p7" />
        <vers num="1.6.8_p8" />
        <vers num="1.6.8_p9" />
        <vers num="1.6.9_p17" />
        <vers num="1.6.9_p18" />
        <vers num="1.6.9_p19" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.2p1" />
        <vers num="1.7.2p2" />
        <vers num="1.7.2p3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0427" published="2010-02-25" name="CVE-2010-0427" modified="2011-01-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz" source="CONFIRM" patch="1">ftp://ftp.sudo.ws/pub/sudo/sudo-1.6.9p21.patch.gz</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=567622" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=567622</ref>
      <ref url="http://www.ubuntu.com/usn/USN-905-1" source="UBUNTU">USN-905-1</ref>
      <ref url="http://www.sudo.ws/cgi-bin/cvsweb/sudo/set_perms.c.diff?r1=1.30.2.7&amp;r2=1.30.2.8" source="CONFIRM">http://www.sudo.ws/cgi-bin/cvsweb/sudo/set_perms.c.diff?r1=1.30.2.7&amp;r2=1.30.2.8</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514489/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0075-1 sudo</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/24/5" source="MLIST">[oss-security] 20100224 Re: CVE assignment notification -- CVE-2010-0427 -- sudo fails to reset group permissions if runas_default set</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/23/4" source="MLIST">[oss-security] 20100223 CVE assignment notification -- CVE-2010-0427 -- sudo fails to reset group permissions if runas_default set</ref>
      <ref url="http://www.gratisoft.us/bugzilla/show_bug.cgi?id=349" source="CONFIRM">http://www.gratisoft.us/bugzilla/show_bug.cgi?id=349</ref>
      <ref url="http://www.gratisoft.us/bugzilla/attachment.cgi?id=255" source="CONFIRM">http://www.gratisoft.us/bugzilla/attachment.cgi?id=255</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-201003-01.xml" source="GENTOO">GLSA-201003-01</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2006" source="DEBIAN">DSA-2006</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2010-0075" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2010-0075</ref>
      <ref url="http://sudo.ws/repos/sudo/rev/aa0b6c01c462" source="CONFIRM">http://sudo.ws/repos/sudo/rev/aa0b6c01c462</ref>
      <ref url="http://securitytracker.com/id?1023658" source="SECTRACK">1023658</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/38803" source="SECUNIA">38803</ref>
      <ref url="http://secunia.com/advisories/38795" source="SECUNIA">38795</ref>
      <ref url="http://secunia.com/advisories/38762" source="SECUNIA">38762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7216" source="OVAL">oval:org.mitre.oval:def:7216</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10946" source="OVAL">oval:org.mitre.oval:def:10946</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.3_p1" />
        <vers num="1.6.3_p2" />
        <vers num="1.6.3_p3" />
        <vers num="1.6.3_p4" />
        <vers num="1.6.3_p5" />
        <vers num="1.6.3_p6" />
        <vers num="1.6.3_p7" />
        <vers num="1.6.4_p1" />
        <vers num="1.6.4_p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5_p1" />
        <vers num="1.6.5_p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.7_p5" />
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p12" />
        <vers num="1.6.8_p5" />
        <vers num="1.6.8_p8" />
        <vers num="1.6.8_p9" />
        <vers num="1.6.9_p17" />
        <vers num="1.6.9_p18" />
        <vers num="1.6.9_p19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0428" published="2010-08-24" name="CVE-2010-0428" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0633.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0633</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0622.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0622</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=568699" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=568699</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_virtualization">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="qspice">
        <vers num="0.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0429" published="2010-08-24" name="CVE-2010-0429" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0633.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0633</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0622.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0622</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=568701" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=568701</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_virtualization">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="qspice">
        <vers num="0.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0431" published="2010-08-24" name="CVE-2010-0431" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0627.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0627</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=568809" source="CONFIRM" patch="1" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=568809</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0622.html" source="REDHAT" adv="1">RHSA-2010:0622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_virtualization">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="kvm">
        <vers num="83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0432" published="2010-04-15" name="CVE-2010-0432" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39489" source="BID">39489</ref>
      <ref url="http://www.bonsai-sec.com/en/research/vulnerabilities/apacheofbiz-multiple-xss-0103.php" source="MISC">http://www.bonsai-sec.com/en/research/vulnerabilities/apacheofbiz-multiple-xss-0103.php</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920382" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920382</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920381" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920381</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920380" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920380</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920379" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920379</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920372" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920372</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920371" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920371</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920370" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920370</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=920369" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=920369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="open_for_business_project">
        <vers prev="1" num="09.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0433" published="2010-03-05" name="CVE-2010-0433" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.2.1a has been released</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.0.6a has been released</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=569774" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=569774</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=567711" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=567711</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1216" source="VUPEN">ADV-2010-1216</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0933" source="VUPEN">ADV-2010-0933</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0916" source="VUPEN">ADV-2010-0916</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0839" source="VUPEN">ADV-2010-0839</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/03/5" source="MLIST">[oss-security] 20100303 OpenSSL (with KRB5) remote crash - CVE-2010-0433</ref>
      <ref url="http://www.openssl.org/news/changelog.html" source="CONFIRM">http://www.openssl.org/news/changelog.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:076" source="MANDRIVA">MDVSA-2010:076</ref>
      <ref url="http://www.mail-archive.com/dovecot@dovecot.org/msg26224.html" source="MLIST">[dovecot] 20100219 segfault - (imap|pop3)-login during nessus scan</ref>
      <ref url="http://secunia.com/advisories/43311" source="SECUNIA">43311</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/39932" source="SECUNIA">39932</ref>
      <ref url="http://secunia.com/advisories/39461" source="SECUNIA">39461</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9856" source="OVAL">oval:org.mitre.oval:def:9856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6718" source="OVAL">oval:org.mitre.oval:def:6718</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12260" source="OVAL">oval:org.mitre.oval:def:12260</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html" source="FEDORA">FEDORA-2010-5357</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html" source="FEDORA">FEDORA-2010-5744</ref>
      <ref url="http://groups.google.com/group/mailing.openssl.users/browse_thread/thread/c3e1ab0034ca4b4c/66aa896c3a78b2f7" source="MISC">http://groups.google.com/group/mailing.openssl.users/browse_thread/thread/c3e1ab0034ca4b4c/66aa896c3a78b2f7</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=19374" source="CONFIRM">http://cvs.openssl.org/chngview?cn=19374</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers num="0.9.8k" />
        <vers num="0.9.8l" />
        <vers prev="1" num="0.9.8m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0434" published="2010-03-05" name="CVE-2010-0434" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM" patch="1" adv="1">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=48359" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=48359</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=570171" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=570171</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56625" source="XF">apache-http-rh-info-disclosure(56625)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1411" source="VUPEN">ADV-2010-1411</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1057" source="VUPEN">ADV-2010-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0994" source="VUPEN">ADV-2010-0994</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0911" source="VUPEN">ADV-2010-0911</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0014.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0014.html</ref>
      <ref url="http://www.securityfocus.com/bid/38494" source="BID">38494</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0175.html" source="REDHAT">RHSA-2010:0175</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0168.html" source="REDHAT">RHSA-2010:0168</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2035" source="DEBIAN">DSA-2035</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829" source="AIXAPAR">PM15829</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" source="AIXAPAR">PM12247</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939" source="AIXAPAR">PM08939</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=918427" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=918427</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=917867" source="CONFIRM">http://svn.apache.org/viewvc?view=revision&amp;revision=917867</ref>
      <ref url="http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/server/protocol.c?r1=917617&amp;r2=917867&amp;pathrev=917867&amp;diff_format=h" source="CONFIRM">http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/server/protocol.c?r1=917617&amp;r2=917867&amp;pathrev=917867&amp;diff_format=h</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/40096" source="SECUNIA">40096</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39632" source="SECUNIA">39632</ref>
      <ref url="http://secunia.com/advisories/39628" source="SECUNIA">39628</ref>
      <ref url="http://secunia.com/advisories/39501" source="SECUNIA">39501</ref>
      <ref url="http://secunia.com/advisories/39115" source="SECUNIA">39115</ref>
      <ref url="http://secunia.com/advisories/39100" source="SECUNIA">39100</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8695" source="OVAL">oval:org.mitre.oval:def:8695</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10358" source="OVAL">oval:org.mitre.oval:def:10358</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000105.html" source="MLIST">[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html" source="FEDORA">FEDORA-2010-6131</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html" source="FEDORA">FEDORA-2010-5942</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0435" published="2010-08-24" name="CVE-2010-0435" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0627.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0627</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0622.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0622</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=570528" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=570528</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0012" source="VUPEN">ADV-2011-0012</ref>
      <ref url="http://secunia.com/advisories/42778" source="SECUNIA">42778</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00000.html" source="SUSE">SUSE-SA:2011:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_virtualization">
        <vers num="2.2" />
      </prod>
      <prod vendor="redhat" name="kvm">
        <vers num="83" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0436" published="2010-04-15" name="CVE-2010-0436" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0879" source="VUPEN" patch="1" adv="1">ADV-2010-0879</ref>
      <ref url="ftp://ftp.kde.org/pub/kde/security_patches/kdebase-workspace-4.3.5-CVE-2010-0436.diff" source="CONFIRM" patch="1">ftp://ftp.kde.org/pub/kde/security_patches/kdebase-workspace-4.3.5-CVE-2010-0436.diff</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=570613" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=570613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57823" source="XF">kde-kdm-privilege-escalation(57823)</ref>
      <ref url="http://www.securityfocus.com/bid/39467" source="BID">39467</ref>
      <ref url="http://www.kde.org/info/security/advisory-20100413-1.txt" source="CONFIRM" adv="1">http://www.kde.org/info/security/advisory-20100413-1.txt</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2037" source="DEBIAN">DSA-2037</ref>
      <ref url="http://secunia.com/advisories/39506" source="SECUNIA">39506</ref>
      <ref url="http://secunia.com/advisories/39481" source="SECUNIA">39481</ref>
      <ref url="http://secunia.com/advisories/39419" source="SECUNIA" adv="1">39419</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2010-0348.html" source="REDHAT">RHSA-2010:0348</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9999" source="OVAL">oval:org.mitre.oval:def:9999</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html" source="SUSE">SUSE-SR:2010:009</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039533.html" source="FEDORA">FEDORA-2010-6605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde_sc">
        <vers num="2.2.0" />
        <vers num="3.5.10" />
        <vers num="4.1.2" />
        <vers num="4.2.2" />
        <vers num="4.3.0" />
        <vers num="4.3.1" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.4.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0437" published="2010-03-24" name="CVE-2010-0437" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=563781" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=563781</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0147.html" source="REDHAT">RHSA-2010:0147</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/04/4" source="MLIST">[oss-security] 20100304 Re: CVE request - kernel: ip6_dst_lookup_tail() NULL pointer dereference</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/11/1" source="MLIST">[oss-security] 20100211 CVE request - kernel: ip6_dst_lookup_tail() NULL pointer dereference</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10061" source="OVAL">oval:org.mitre.oval:def:10061</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e550dfb0c2c31b6363aa463a035fc9f8dcaa3c9b" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e550dfb0c2c31b6363aa463a035fc9f8dcaa3c9b</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=11469" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=11469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers prev="1" num="2.6.26.8" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0438" published="2010-02-09" name="CVE-2010-0438" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38146" source="BID">38146</ref>
      <ref url="http://www.otrs.org/news/2010/otrs_2-4-7/" source="CONFIRM">http://www.otrs.org/news/2010/otrs_2-4-7/</ref>
      <ref url="http://www.osvdb.org/62181" source="OSVDB">62181</ref>
      <ref url="http://source.otrs.org/viewvc.cgi/otrs/Kernel/System/Ticket.pm?view=log" source="CONFIRM">http://source.otrs.org/viewvc.cgi/otrs/Kernel/System/Ticket.pm?view=log</ref>
      <ref url="http://secunia.com/advisories/38544" source="SECUNIA">38544</ref>
      <ref url="http://secunia.com/advisories/38507" source="SECUNIA" adv="1">38507</ref>
      <ref url="http://otrs.org/releases/2.4.7/" source="CONFIRM">http://otrs.org/releases/2.4.7/</ref>
      <ref url="http://otrs.org/advisory/OSA-2010-01-en/" source="CONFIRM" adv="1">http://otrs.org/advisory/OSA-2010-01-en/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="otrs" name="otrs">
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0439" published="2010-03-26" name="CVE-2010-0439" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38924" source="BID">38924</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510306/100/0/threaded" source="BUGTRAQ">20100324 Multiple vulnerabilities in Deliver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chip_salzenberg" name="deliver">
        <vers num="2.1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0440" published="2010-02-03" name="CVE-2010-0440" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://tools.cisco.com/security/center/viewAlert.x?alertId=19843

"Cisco Secure Desktop versions prior to 3.5 are vulnerable. Cisco Secure Desktop is a component of Cisco ASA 5500 Series Adaptive Security Appliances.  Cisco ASA appliances are vulnerable only if the Cisco Secure Desktop feature has been enabled.  Cisco ASA appliance versions prior to 8.2(1), 8.1(2.7), and 8.0(5) are vulnerable."</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=19843" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=19843</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0273" source="VUPEN" adv="1">ADV-2010-0273</ref>
      <ref url="http://www.securityfocus.com/bid/37960" source="BID">37960</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509290/100/0/threaded" source="BUGTRAQ">20100201 [CORE-2010-0106] Cisco Secure Desktop XSS/JavaScript Injection</ref>
      <ref url="http://www.coresecurity.com/content/cisco-secure-desktop-xss" source="MISC">http://www.coresecurity.com/content/cisco-secure-desktop-xss</ref>
      <ref url="http://secunia.com/advisories/38397" source="SECUNIA" adv="1">38397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_desktop">
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1.27" />
        <vers num="3.1.1.33" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers prev="1" num="3.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0441" published="2010-02-04" name="CVE-2010-0441" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.1.diff" source="CONFIRM" patch="1">http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.1.diff</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.0.diff" source="CONFIRM" patch="1">http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.0.diff</ref>
      <ref url="https://issues.asterisk.org/view.php?id=16724" source="CONFIRM">https://issues.asterisk.org/view.php?id=16724</ref>
      <ref url="https://issues.asterisk.org/view.php?id=16634" source="CONFIRM">https://issues.asterisk.org/view.php?id=16634</ref>
      <ref url="https://issues.asterisk.org/view.php?id=16517" source="CONFIRM">https://issues.asterisk.org/view.php?id=16517</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0289" source="VUPEN" adv="1">ADV-2010-0289</ref>
      <ref url="http://www.securityfocus.com/bid/38047" source="BID">38047</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509327/100/0/threaded" source="BUGTRAQ">20100202 AST-2010-001: T.38 Remote Crash Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1023532" source="SECTRACK">1023532</ref>
      <ref url="http://secunia.com/advisories/39096" source="SECUNIA">39096</ref>
      <ref url="http://secunia.com/advisories/38395" source="SECUNIA" adv="1">38395</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html" source="FEDORA">FEDORA-2010-3724</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-001.html" source="CONFIRM">http://downloads.asterisk.org/pub/security/AST-2010-001.html</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.2.diff" source="CONFIRM">http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.2.diff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk">
        <vers num="1.6.0" />
        <vers num="1.6.0.1" />
        <vers num="1.6.0.10" />
        <vers num="1.6.0.12" />
        <vers num="1.6.0.13" />
        <vers num="1.6.0.14" />
        <vers num="1.6.0.15" />
        <vers num="1.6.0.16-rc1" />
        <vers num="1.6.0.16-rc2" />
        <vers num="1.6.0.17" />
        <vers num="1.6.0.18" />
        <vers num="1.6.0.18-rc1" />
        <vers num="1.6.0.18-rc2" />
        <vers num="1.6.0.18-rc3" />
        <vers num="1.6.0.19" />
        <vers num="1.6.0.2" />
        <vers num="1.6.0.20" />
        <vers num="1.6.0.20-rc1" />
        <vers num="1.6.0.21" />
        <vers num="1.6.0.21-rc1" />
        <vers num="1.6.0.3" />
        <vers num="1.6.0.5" />
        <vers num="1.6.0.6" />
        <vers num="1.6.0.7" />
        <vers num="1.6.0.8" />
        <vers num="1.6.0.9" />
        <vers num="1.6.1.0" />
        <vers num="1.6.1.1" />
        <vers num="1.6.1.10" />
        <vers num="1.6.1.10-rc1" />
        <vers num="1.6.1.10-rc2" />
        <vers num="1.6.1.10-rc3" />
        <vers num="1.6.1.11" />
        <vers num="1.6.1.12" />
        <vers num="1.6.1.12-rc1" />
        <vers num="1.6.1.13" />
        <vers num="1.6.1.13-rc1" />
        <vers num="1.6.1.2" />
        <vers num="1.6.1.4" />
        <vers num="1.6.1.5" />
        <vers num="1.6.1.6" />
        <vers num="1.6.1.7-rc1" />
        <vers num="1.6.1.7-rc2" />
        <vers num="1.6.1.8" />
        <vers num="1.6.1.9" />
        <vers num="1.6.10-rc1" />
        <vers num="1.6.10-rc2" />
        <vers num="1.6.2.1" />
        <vers num="1.6.2.1-rc1" />
        <vers num="c.3.1.0" edition="" />
        <vers num="c.3.1.0" edition=":business" />
        <vers num="c.3.1.1" edition="" />
        <vers num="c.3.1.1" edition=":business" />
        <vers num="c.3.2.2" edition="" />
        <vers num="c.3.2.2" edition=":business" />
        <vers num="c.3.3.3" edition="" />
        <vers num="c.3.3.3" edition=":business" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0442" published="2010-02-02" name="CVE-2010-0442" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559259" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559259</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=559194" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=559194</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55902" source="XF">postgresql-substring-bo(55902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1221" source="VUPEN">ADV-2010-1221</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1207" source="VUPEN">ADV-2010-1207</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1197" source="VUPEN">ADV-2010-1197</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1022" source="VUPEN">ADV-2010-1022</ref>
      <ref url="http://www.securityfocus.com/bid/37973" source="BID">37973</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0429.html" source="REDHAT">RHSA-2010:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0428.html" source="REDHAT">RHSA-2010:0428</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0427.html" source="REDHAT">RHSA-2010:0427</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/27/5" source="MLIST">[oss-security] 20100127 Re: CVE id request: postgresql bitsubstr overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:103" source="MANDRIVA">MDVSA-2010:103</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2051" source="DEBIAN">DSA-2051</ref>
      <ref url="http://ubuntu.com/usn/usn-933-1" source="UBUNTU">USN-933-1</ref>
      <ref url="http://securitytracker.com/id?1023510" source="SECTRACK">1023510</ref>
      <ref url="http://secunia.com/advisories/39939" source="SECUNIA">39939</ref>
      <ref url="http://secunia.com/advisories/39820" source="SECUNIA">39820</ref>
      <ref url="http://secunia.com/advisories/39566" source="SECUNIA">39566</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9720" source="OVAL">oval:org.mitre.oval:def:9720</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.html" source="MISC">http://intevydis.blogspot.com/2010/01/postgresql-8023-bitsubstr-overflow.html</ref>
      <ref url="http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=b15087cb39ca9e4bde3c8920fcee3741045d2b83" source="CONFIRM">http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=b15087cb39ca9e4bde3c8920fcee3741045d2b83</ref>
      <ref url="http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=75dea10196c31d98d98c0bafeeb576ae99c09b12" source="CONFIRM">http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=75dea10196c31d98d98c0bafeeb576ae99c09b12</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567058</ref>
      <ref url="http://archives.postgresql.org/pgsql-hackers/2010-01/msg00634.php" source="MLIST">[pgsql-hackers] 20100107 Re: Patch: Allow substring/replace() to get/set bit values</ref>
      <ref url="http://archives.postgresql.org/pgsql-committers/2010-01/msg00125.php" source="MLIST">[pgsql-committers] 20100107 pgsql: Make bit/varbit substring() treat any negative length as meaning</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.0.23" />
        <vers num="8.1.11" />
        <vers num="8.3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0443" published="2010-02-04" name="CVE-2010-0443" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0286" source="VUPEN" patch="1" adv="1">ADV-2010-0286</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126520981100671&amp;w=2" source="HP" patch="1" adv="1">HPSBOV02505</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126520981100671&amp;w=2" source="HP" patch="1" adv="1">HPSBOV02505</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56062" source="XF">openvms-rms-privilege-escalation(56062)</ref>
      <ref url="http://www.securityfocus.com/bid/38048" source="BID">38048</ref>
      <ref url="http://secunia.com/advisories/38366" source="SECUNIA" adv="1">38366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms_rms">
        <vers num="vms83a_rms-v1000" />
        <vers num="vms83a_update-v1100" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0444" published="2010-02-09" name="CVE-2010-0444" modified="2010-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38150" source="BID">38150</ref>
      <ref url="http://securitytracker.com/id?1023555" source="SECTRACK">1023555</ref>
      <ref url="http://osvdb.org/62213" source="OSVDB">62213</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126566258722040&amp;w=2" source="HP" adv="1">HPSBMA02487</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126566258722040&amp;w=2" source="HP" adv="1">HPSBMA02487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="operations_agent">
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0445" published="2010-02-11" name="CVE-2010-0445" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38528" source="SECUNIA" adv="1">38528</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126582291202560&amp;w=2" source="HP">HPSBMA02484</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126582291202560&amp;w=2" source="HP">HPSBMA02484</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="network_node_manager">
        <vers num="8.10" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0446" published="2010-02-12" name="CVE-2010-0446" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability on the HP DreamScreen 100 and 130 with firmware before 1.6.0.0, when using a web-connected configuration, allows remote attackers to obtain sensitive information via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38190" source="BID" patch="1">38190</ref>
      <ref url="http://securitytracker.com/id?1023581" source="SECTRACK">1023581</ref>
      <ref url="http://secunia.com/advisories/38536" source="SECUNIA">38536</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126592424225647&amp;w=2" source="HP">HPSBPI02507</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126592424225647&amp;w=2" source="HP">HPSBPI02507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="dreamscreen">
        <vers num="100" />
        <vers num="130" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0447" published="2010-03-10" name="CVE-2010-0447" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56757" source="XF">hp-performance-unspec-command-exec(56757)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-026" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0555" source="VUPEN" adv="1">ADV-2010-0555</ref>
      <ref url="http://www.securityfocus.com/bid/38611" source="BID">38611</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509984/100/0/threaded" source="BUGTRAQ">20100309 ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38899" source="SECUNIA" adv="1">38899</ref>
      <ref url="http://osvdb.org/62797" source="OSVDB">62797</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126815897824020&amp;w=2" source="HP">SSRT090065</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126815897824020&amp;w=2" source="HP">SSRT090065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_performance_insight">
        <vers prev="1" num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0448" published="2010-03-31" name="CVE-2010-0448" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to obtain "unauthorized access to data" via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02490</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02490</ref>
      <ref url="http://www.securitytracker.com/id?1023765" source="SECTRACK">1023765</ref>
      <ref url="http://www.securityfocus.com/bid/39059" source="BID">39059</ref>
      <ref url="http://secunia.com/advisories/39187" source="SECUNIA" adv="1">39187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="soa_registry_foundation">
        <vers num="6.63" />
        <vers num="6.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0449" published="2010-03-31" name="CVE-2010-0449" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">SSRT090222</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">SSRT090222</ref>
      <ref url="http://www.securitytracker.com/id?1023765" source="SECTRACK">1023765</ref>
      <ref url="http://www.securityfocus.com/bid/39060" source="BID">39060</ref>
      <ref url="http://secunia.com/advisories/39187" source="SECUNIA" adv="1">39187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="soa_registry_foundation">
        <vers num="6.63" />
        <vers num="6.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0450" published="2010-03-31" name="CVE-2010-0450" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:N)" CVSS_score="8.5" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote authenticated users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">SSRT090222</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996774125378&amp;w=2" source="HP" patch="1" adv="1">SSRT090222</ref>
      <ref url="http://www.securitytracker.com/id?1023765" source="SECTRACK">1023765</ref>
      <ref url="http://www.securityfocus.com/bid/39061" source="BID">39061</ref>
      <ref url="http://secunia.com/advisories/39187" source="SECUNIA" adv="1">39187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="soa_registry_foundation">
        <vers num="6.63" />
        <vers num="6.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0451" published="2010-03-29" name="CVE-2010-0451" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126962272413767&amp;w=2" source="HP" patch="1" adv="1">HPSBUX02509</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126962272413767&amp;w=2" source="HP" patch="1" adv="1">HPSBUX02509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57216" source="XF">hpux-oncplus-weak-security(57216)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0731" source="VUPEN">ADV-2010-0731</ref>
      <ref url="http://www.securityfocus.com/bid/38982" source="BID">38982</ref>
      <ref url="http://securitytracker.com/id?1023758" source="SECTRACK">1023758</ref>
      <ref url="http://secunia.com/advisories/39111" source="SECUNIA" adv="1">39111</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12025" source="OVAL">oval:org.mitre.oval:def:12025</ref>
      <ref url="http://osvdb.org/63243" source="OSVDB">63243</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.31" />
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0452" published="2010-03-29" name="CVE-2010-0452" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38961" source="BID">38961</ref>
      <ref url="http://www.osvdb.org/63175" source="OSVDB">63175</ref>
      <ref url="http://securitytracker.com/id?1023749" source="SECTRACK">1023749</ref>
      <ref url="http://secunia.com/advisories/39105" source="SECUNIA" adv="1">39105</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126953216625011&amp;w=2" source="HP" adv="1">SSRT080064</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126953216625011&amp;w=2" source="HP" adv="1">SSRT080064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="project_and_portfolio_management_center">
        <vers prev="1" num="7.1" edition="sp10" />
        <vers prev="1" num="7.5" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0453" published="2010-02-03" name="CVE-2010-0453" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0270" source="VUPEN" patch="1" adv="1">ADV-2010-0270</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-143913-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-143913-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55991" source="XF">solaris-microcode-dos(55991)</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2010-001.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2010-001.txt</ref>
      <ref url="http://www.securityfocus.com/bid/38016" source="BID">38016</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509276/100/0/threaded" source="BUGTRAQ">20100131 [TKADV2010-001] Oracle Solaris UCODE_GET_VERSION IOCTL Kernel NULL Pointer Dereference</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021799.1-1" source="SUNALERT">1021799</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-275910-1" source="SUNALERT">275910</ref>
      <ref url="http://secunia.com/advisories/38452" source="SECUNIA" adv="1">38452</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6959" source="OVAL">oval:org.mitre.oval:def:6959</ref>
      <ref url="http://osvdb.org/62046" source="OSVDB">62046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":x86" />
        <vers num="snv_112" edition="" />
        <vers num="snv_112" edition=":x86" />
        <vers num="snv_113" edition="" />
        <vers num="snv_113" edition=":x86" />
        <vers num="snv_114" edition="" />
        <vers num="snv_114" edition=":x86" />
        <vers num="snv_115" edition="" />
        <vers num="snv_115" edition=":x86" />
        <vers num="snv_116" edition="" />
        <vers num="snv_116" edition=":x86" />
        <vers num="snv_117" edition="" />
        <vers num="snv_117" edition=":x86" />
        <vers num="snv_118" edition="" />
        <vers num="snv_118" edition=":x86" />
        <vers num="snv_119" edition="" />
        <vers num="snv_119" edition=":x86" />
        <vers num="snv_120" edition="" />
        <vers num="snv_120" edition=":x86" />
        <vers num="snv_121" edition="" />
        <vers num="snv_121" edition=":x86" />
        <vers num="snv_122" edition="" />
        <vers num="snv_122" edition=":x86" />
        <vers num="snv_123" edition="" />
        <vers num="snv_123" edition=":x86" />
        <vers num="snv_124" edition="" />
        <vers num="snv_124" edition=":x86" />
        <vers num="snv_125" edition="" />
        <vers num="snv_125" edition=":x86" />
        <vers num="snv_126" edition="" />
        <vers num="snv_126" edition=":x86" />
        <vers num="snv_127" edition="" />
        <vers num="snv_127" edition=":x86" />
        <vers num="snv_128" edition="" />
        <vers num="snv_128" edition=":x86" />
        <vers num="snv_129" edition="" />
        <vers num="snv_129" edition=":x86" />
        <vers num="snv_130" edition="" />
        <vers num="snv_130" edition=":x86" />
        <vers num="snv_131" edition="" />
        <vers num="snv_131" edition=":x86" />
        <vers num="snv_132" edition="" />
        <vers num="snv_132" edition=":x86" />
        <vers num="snv_133" edition="" />
        <vers num="snv_133" edition=":x86" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0454" published="2010-01-28" name="CVE-2010-0454" modified="2010-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in cgi/cgilua.exe/sys/start.htm in Publique! 2.3 allows remote attackers to execute arbitrary SQL commands via the sid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509142/100/0/threaded" source="BUGTRAQ">20100125 Publique! CMS SQL Injection Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/38302" source="SECUNIA" adv="1">38302</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/publique-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/publique-sql.txt</ref>
      <ref url="http://osvdb.org/61941" source="OSVDB">61941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabricadigital" name="publique!">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0455" published="2010-01-28" name="CVE-2010-0455" modified="2010-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in forum/viewtopic.php in PunBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the pid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55853" source="XF">punbb-viewtopic-xss(55853)</ref>
      <ref url="http://www.securityfocus.com/bid/37930" source="BID">37930</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/punbb13-xss.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/punbb13-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="punbb" name="punbb">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0456" published="2010-01-28" name="CVE-2010-0456" modified="2010-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55829" source="XF">gameserver-grp-sql-injection(55829)</ref>
      <ref url="http://www.securityfocus.com/bid/37934" source="BID">37934</ref>
      <ref url="http://www.securityfocus.com/bid/37920" source="BID">37920</ref>
      <ref url="http://www.exploit-db.com/exploits/11222" source="EXPLOIT-DB">11222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indianpulses" name="com_gameserver">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0457" published="2010-01-28" name="CVE-2010-0457" modified="2010-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55849" source="XF">magicportal-home-sql-injection(55849)</ref>
      <ref url="http://www.exploit-db.com/exploits/11235" source="EXPLOIT-DB">11235</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/magicportal-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/magicportal-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="a3malnet" name="magic-portal">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0458" published="2010-01-28" name="CVE-2010-0458" modified="2011-01-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to index.php and the (2) note parameter to blog.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55862" source="XF">blogsystem-blog-sql-injection(55862)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55818" source="XF">blogsystem-index-sql-injection(55818)</ref>
      <ref url="http://www.securityfocus.com/bid/37911" source="BID">37911</ref>
      <ref url="http://www.exploit-db.com/exploits/11216" source="EXPLOIT-DB">11216</ref>
      <ref url="http://packetstormsecurity.org/0512-exploits/blog12SQL.txt" source="MISC">http://packetstormsecurity.org/0512-exploits/blog12SQL.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netartmedia" name="blog_system">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0459" published="2010-01-28" name="CVE-2010-0459" modified="2010-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55841" source="XF">mochigames-index-sql-injection(55841)</ref>
      <ref url="http://www.securityfocus.com/bid/37931" source="BID">37931</ref>
      <ref url="http://www.exploit-db.com/exploits/11243" source="EXPLOIT-DB">11243</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlamochigames-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlamochigames-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yoflash" name="com_mochigames">
        <vers num="0.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0460" published="2010-01-28" name="CVE-2010-0460" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55859" source="XF">supportsuite-contents-xss(55859)</ref>
      <ref url="http://www.securityfocus.com/bid/37947" source="BID">37947</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509122/100/0/threaded" source="BUGTRAQ">20100121 Kayako SupportSuite Multiple Persistent Cross Site Scripting (Current Versions)</ref>
      <ref url="http://secunia.com/advisories/38322" source="SECUNIA" adv="1">38322</ref>
      <ref url="http://packetstormsecurity.org/1001-advisories/kayako-xss.txt" source="MISC">http://packetstormsecurity.org/1001-advisories/kayako-xss.txt</ref>
      <ref url="http://osvdb.org/61928" source="OSVDB">61928</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kayako" name="esupport">
        <vers prev="1" num="3.60.04" />
      </prod>
      <prod vendor="kayako" name="supportsuite">
        <vers num="3.0" />
        <vers num="3.00.26" />
        <vers num="3.00.32" />
        <vers num="3.10.00" />
        <vers num="3.10.02" />
        <vers num="3.11.00" />
        <vers num="3.11.01" />
        <vers num="3.20.02" />
        <vers num="3.30" edition="rc2" />
        <vers num="3.30" edition="rc3" />
        <vers num="3.50.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0461" published="2010-01-28" name="CVE-2010-0461" modified="2010-01-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php.</descript>
      <descript source="nvd">Exploit PoC reference links indicate a prerequisite of privileged authenticated user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55846" source="XF">casino-indexphp-sql-injection(55846)</ref>
      <ref url="http://www.securityfocus.com/bid/37938" source="BID">37938</ref>
      <ref url="http://www.exploit-db.com/exploits/11237" source="EXPLOIT-DB">11237</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlacasino1-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlacasino1-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_casino">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0462" published="2010-01-28" name="CVE-2010-0462" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55899" source="XF">db2-sysibm-bo(55899)</ref>
      <ref url="http://www.securityfocus.com/bid/37976" source="BID">37976</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21432298" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21432298</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21426108" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21426108</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC65935" source="AIXAPAR">IC65935</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC65933" source="AIXAPAR">IC65933</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC65922" source="AIXAPAR">IC65922</ref>
      <ref url="http://securitytracker.com/id?1023509" source="SECTRACK">1023509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14518" source="OVAL">oval:org.mitre.oval:def:14518</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/ibm-db2-97-heap-overflow.html" source="MISC">http://intevydis.blogspot.com/2010/01/ibm-db2-97-heap-overflow.html</ref>
      <ref url="ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT" source="CONFIRM">ftp://public.dhe.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="9.1" edition="fp1" />
        <vers num="9.1" edition="fp2" />
        <vers num="9.1" edition="fp2a" />
        <vers num="9.1" edition="fp3" />
        <vers num="9.1" edition="fp3a" />
        <vers num="9.1" edition="fp4" />
        <vers num="9.1" edition="fp4a" />
        <vers num="9.1" edition="fp5" />
        <vers num="9.1" edition="fp6" />
        <vers num="9.1" edition="fp6a" />
        <vers num="9.1" edition="fp7" />
        <vers num="9.1" edition="fp7a" />
        <vers num="9.1" edition="fp8" />
        <vers num="9.5" edition="fp1" />
        <vers num="9.5" edition="fp2" />
        <vers num="9.5" edition="fp2a" />
        <vers num="9.5" edition="fp3" />
        <vers num="9.5" edition="fp3a" />
        <vers num="9.5" edition="fp3b" />
        <vers num="9.5" edition="fp4" />
        <vers num="9.5" edition="fp4a" />
        <vers num="9.5" edition="fp5" />
        <vers num="9.7" edition="fp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0463" published="2010-01-29" name="CVE-2010-0463" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.horde.org/ticket/8836" source="CONFIRM" patch="1">http://bugs.horde.org/ticket/8836</ref>
      <ref url="https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail" source="MISC">https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56052" source="XF">horde-dns-info-disclosure(56052)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="imp">
        <vers num="2.0" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" edition="rc1" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.1.3" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers prev="1" num="4.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0464" published="2010-01-29" name="CVE-2010-0464" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.roundcube.net/ticket/1486449" source="CONFIRM" patch="1">http://trac.roundcube.net/ticket/1486449</ref>
      <ref url="https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail" source="MISC">https://secure.grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_and_Webmail</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:048" source="MANDRIVA">MDVSA-2010:048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roundcube" name="roundcube_webmail">
        <vers num="0.1" edition="alpha" />
        <vers num="0.1" edition="beta" />
        <vers num="0.1" edition="beta2" />
        <vers num="0.1" edition="rc1" />
        <vers num="0.1" edition="rc2" />
        <vers num="0.1.1" />
        <vers num="0.2" edition="alpha" />
        <vers num="0.2" edition="beta" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.3" />
        <vers prev="1" num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0465" published="2010-03-19" name="CVE-2010-0465" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the online Documents functionality in SugarCRM 5.2.x before 5.2.0l and 5.5.x before 5.5.0a allows remote authenticated users to inject arbitrary web script or HTML via the Document Name field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.sugarcrm.com/crm/support/bugs.html?task=view&amp;caseID=db4489b7-b5a8-4a6d-555b-4b9ffa7b4ffa" source="CONFIRM">http://www.sugarcrm.com/crm/support/bugs.html?task=view&amp;caseID=db4489b7-b5a8-4a6d-555b-4b9ffa7b4ffa</ref>
      <ref url="http://www.securityfocus.com/bid/38772" source="BID">38772</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510116/100/0/threaded" source="BUGTRAQ">20100316 SugarCRM Stored XSS vulnerability</ref>
      <ref url="http://secunia.com/advisories/38962" source="SECUNIA">38962</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sugarcrm" name="sugarcrm">
        <vers num="5.2.0g" />
        <vers num="5.2a" />
        <vers num="5.2c" />
        <vers num="5.2d" />
        <vers num="5.2e" />
        <vers num="5.2f" />
        <vers num="5.2g" />
        <vers num="5.2h" />
        <vers num="5.5" edition="beta1" />
        <vers num="5.5" edition="beta2" />
        <vers num="5.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0467" published="2010-02-02" name="CVE-2010-0467" modified="2010-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55953" source="XF">ccnewsletter-index-dir-traversal(55953)</ref>
      <ref url="http://www.securityfocus.com/bid/37987" source="BID">37987</ref>
      <ref url="http://www.exploit-db.com/exploits/11282" source="EXPLOIT-DB">11282</ref>
      <ref url="http://www.exploit-db.com/exploits/11277" source="EXPLOIT-DB">11277</ref>
      <ref url="http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html" source="CONFIRM" adv="1">http://www.chillcreations.com/en/blog/ccnewsletter-joomla-newsletter/ccnewsletter-106-security-release.html</ref>
      <ref url="http://secunia.com/advisories/38378" source="SECUNIA" adv="1">38378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chillcreations" name="com_ccnewsletter">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0468" published="2010-02-02" name="CVE-2010-0468" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55955" source="XF">commonspot-longproc-xss(55955)</ref>
      <ref url="http://www.securityfocus.com/bid/37986" source="BID">37986</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509239/100/0/threaded" source="BUGTRAQ">20100128 PR09-19: Cross-Site Scripting (XSS) on CommonSpot server</ref>
      <ref url="http://osvdb.org/62087" source="OSVDB">62087</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0601.html" source="FULLDISC">20100128 PR09-19: Cross-Site Scripting (XSS) on CommonSpot server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paperthin" name="commonspot_content_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0469" published="2010-02-02" name="CVE-2010-0469" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Files2Links F2L 3000 appliance 4.0.0, and possibly other versions and models, allows remote attackers to execute arbitrary SQL commands via unspecified parameters to the login page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55950" source="XF">f2l3000-login-sql-injection(55950)</ref>
      <ref url="http://secunia.com/advisories/38310" source="SECUNIA" adv="1">38310</ref>
      <ref url="http://packetstormsecurity.org/1001-advisories/DDIVRT-2009-27.txt" source="MISC">http://packetstormsecurity.org/1001-advisories/DDIVRT-2009-27.txt</ref>
      <ref url="http://osvdb.org/61976" source="OSVDB">61976</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0499.html" source="FULLDISC">20100125 DDIVRT-2009-27 F2L-3000 files2links SQL Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="files2links" name="f2l_3000_appliance">
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0470" published="2010-02-02" name="CVE-2010-0470" modified="2010-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38004" source="BID">38004</ref>
      <ref url="http://secunia.com/advisories/38309" source="SECUNIA" adv="1">38309</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/comtrend-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/comtrend-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comtrend" name="ct-507it_adsl_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0471" published="2010-02-02" name="CVE-2010-0471" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the comment submission interface (includes/comment.php) in Enano CMS before 1.0.6pl1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://enanocms.org/Release_notes/1.0.6pl1" source="CONFIRM" patch="1" adv="1">http://enanocms.org/Release_notes/1.0.6pl1</ref>
      <ref url="http://www.osvdb.org/61974" source="OSVDB">61974</ref>
      <ref url="http://secunia.com/advisories/38253" source="SECUNIA" adv="1">38253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enanocms" name="enanocms">
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.2b1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers prev="1" num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0472" published="2010-02-02" name="CVE-2010-0472" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38018" source="BID">38018</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21432298" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21432298</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC68762" source="AIXAPAR">IC68762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14289" source="OVAL">oval:org.mitre.oval:def:14289</ref>
      <ref url="http://intevydis.blogspot.com/2010/01/ibm-db2-97-kuddb2-dos.html" source="MISC">http://intevydis.blogspot.com/2010/01/ibm-db2-97-kuddb2-dos.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers num="9.7.0.1" edition="" />
        <vers num="9.7.0.1" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0475" published="2010-05-14" name="CVE-2010-0475" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58624" source="XF">paloalto-edituser-xss(58624)</ref>
      <ref url="http://www.jeromiejackson.com/index.php?view=article&amp;id=83:palo-alto-cross-site-scripting-vulnerability&amp;tmpl=component&amp;print=1&amp;layout=default&amp;page=" source="MISC">http://www.jeromiejackson.com/index.php?view=article&amp;id=83:palo-alto-cross-site-scripting-vulnerability&amp;tmpl=component&amp;print=1&amp;layout=default&amp;page=</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-05/0086.html" source="BUGTRAQ">20100512 Palo Alto Network Vulnerability - Cross-Site Scripting (XSS)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palo_alto_networks" name="firewall">
        <vers prev="1" num="3.0.8" />
        <vers prev="1" num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0476" published="2010-04-14" name="CVE-2010-0476" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx" source="MS" patch="1" adv="1">MS10-020</ref>
      <ref url="http://www.securityfocus.com/bid/39336" source="BID">39336</ref>
      <ref url="http://secunia.com/advisories/39372" source="SECUNIA">39372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6918" source="OVAL">oval:org.mitre.oval:def:6918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="beta" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0477" published="2010-04-14" name="CVE-2010-0477" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx" source="MS" patch="1" adv="1">MS10-020</ref>
      <ref url="http://secunia.com/advisories/39372" source="SECUNIA">39372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6859" source="OVAL">oval:org.mitre.oval:def:6859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0478" published="2010-04-14" name="CVE-2010-0478" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-025.mspx" source="MS" patch="1" adv="1">MS10-025</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7001" source="OVAL">oval:org.mitre.oval:def:7001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0479" published="2010-04-14" name="CVE-2010-0479" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-023.mspx" source="MS" patch="1" adv="1">MS10-023</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7141" source="OVAL">oval:org.mitre.oval:def:7141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="publisher">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0480" published="2010-04-14" name="CVE-2010-0480" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-026.mspx" source="MS" patch="1" adv="1">MS10-026</ref>
      <ref url="http://securityreason.com/securityalert/8336" source="SREASON">8336</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7441" source="OVAL">oval:org.mitre.oval:def:7441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0481" published="2010-04-14" name="CVE-2010-0481" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39374" source="SECUNIA">39374</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6770" source="OVAL">oval:org.mitre.oval:def:6770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0482" published="2010-04-14" name="CVE-2010-0482" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39374" source="SECUNIA">39374</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7176" source="OVAL">oval:org.mitre.oval:def:7176</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0483" published="2010-03-03" name="CVE-2010-0483" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/612021" source="CERT-VN">VU#612021</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-022.mspx" source="MS" patch="1" adv="1">MS10-022</ref>
      <ref url="https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb" source="MISC">https://www.metasploit.com/svn/framework3/trunk/modules/exploits/windows/browser/ie_winhlp32.rb</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56558" source="XF">ms-win-msgbox-code-execution(56558)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0485" source="VUPEN" adv="1">ADV-2010-0485</ref>
      <ref url="http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/" source="MISC">http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/</ref>
      <ref url="http://www.securityfocus.com/bid/38463" source="BID">38463</ref>
      <ref url="http://www.osvdb.org/62632" source="OSVDB">62632</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/981169.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/981169.mspx</ref>
      <ref url="http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk" source="MISC">http://www.computerworld.com/s/article/9163298/New_zero_day_involves_IE_puts_Windows_XP_users_at_risk</ref>
      <ref url="http://securitytracker.com/id?1023668" source="SECTRACK">1023668</ref>
      <ref url="http://secunia.com/advisories/38727" source="SECUNIA" adv="1">38727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8654" source="OVAL">oval:org.mitre.oval:def:8654</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7170" source="OVAL">oval:org.mitre.oval:def:7170</ref>
      <ref url="http://isec.pl/vulnerabilities10.html" source="MISC">http://isec.pl/vulnerabilities10.html</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt</ref>
      <ref url="http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0484" published="2010-06-08" name="CVE-2010-0484" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx" source="MS" patch="1" adv="1">MS10-032</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511769/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Windows Kernel "GetDCEx()" Memory Corruption Vulnerability (CVE-2010-0484)</ref>
      <ref url="http://www.opera.com/support/kb/view/954/" source="CONFIRM">http://www.opera.com/support/kb/view/954/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7609" source="OVAL">oval:org.mitre.oval:def:7609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0485" published="2010-06-08" name="CVE-2010-0485" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx" source="MS" patch="1" adv="1">MS10-032</ref>
      <ref url="http://www.opera.com/support/kb/view/954/" source="CONFIRM">http://www.opera.com/support/kb/view/954/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6948" source="OVAL">oval:org.mitre.oval:def:6948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0486" published="2010-04-14" name="CVE-2010-0486" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-019.mspx" source="MS" patch="1" adv="1">MS10-019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6787" source="OVAL">oval:org.mitre.oval:def:6787</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0487" published="2010-04-14" name="CVE-2010-0487" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-019.mspx" source="MS" patch="1" adv="1">MS10-019</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6886" source="OVAL">oval:org.mitre.oval:def:6886</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0488" published="2010-03-31" name="CVE-2010-0488" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 8 is not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39028" source="BID" patch="1">39028</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7840" source="OVAL">oval:org.mitre.oval:def:7840</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000011.html" source="JVNDB">JVNDB-2010-000011</ref>
      <ref url="http://jvn.jp/en/jp/JVN49467403/index.html" source="JVN">JVN#49467403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0489" published="2010-03-31" name="CVE-2010-0489" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 8 is not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39026" source="BID" patch="1">39026</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7774" source="OVAL">oval:org.mitre.oval:def:7774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0490" published="2010-03-31" name="CVE-2010-0490" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 5.01 Service Pack 4 is not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39031" source="BID" patch="1">39031</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8302" source="OVAL">oval:org.mitre.oval:def:8302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7" />
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0491" published="2010-03-31" name="CVE-2010-0491" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 7 and Internet Explorer 8 are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39027" source="BID" patch="1">39027</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8421" source="OVAL">oval:org.mitre.oval:def:8421</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=864" source="IDEFENSE">20100330 Microsoft Internet Explorer 'onreadystatechange' Use After Free Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0492" published="2010-03-31" name="CVE-2010-0492" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 6 and Internet Explorer 7 are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39030" source="BID" patch="1">39030</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-033" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510506/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-033: Microsoft Internet Explorer TIME2 Behavior Remote Code Execution Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7722" source="OVAL">oval:org.mitre.oval:def:7722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0494" published="2010-03-31" name="CVE-2010-0494" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 5.01 Service Pack 4 is not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39047" source="BID" patch="1">39047</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8553" source="OVAL">oval:org.mitre.oval:def:8553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
        <vers num="8.0.6001" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0496" published="2010-02-03" name="CVE-2010-0496" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55949" source="XF">serversman-iphone-ipod-dos(55949)</ref>
      <ref url="http://secunia.com/advisories/38315" source="SECUNIA" adv="1">38315</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0580.html" source="FULLDISC">20100127 Apple Iphone/Ipod - Serversman 3.1.5 HTTP Remote DoS exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebit" name="serversman">
        <vers num="3.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0497" published="2010-03-30" name="CVE-2010-0497" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Disk Images in Apple Mac OS X before 10.6.3 does not provide the expected warning for an unsafe file type in an internet enabled disk image, which makes it easier for user-assisted remote attackers to execute arbitrary code via a package file type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0498" published="2010-03-30" name="CVE-2010-0498" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0500" published="2010-03-30" name="CVE-2010-0500" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0501" published="2010-03-30" name="CVE-2010-0501" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote authenticated users to read arbitrary files via crafted filenames.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects Mac OS X Server systems.'</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0502" published="2010-03-30" name="CVE-2010-0502" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects Mac OS X Server systems.</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0503" published="2010-03-30" name="CVE-2010-0503" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Use-after-free vulnerability in iChat Server in Apple Mac OS X Server 10.5.8 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects Mac OS X Server systems, and does not affect versions 10.6 or later'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0504" published="2010-03-30" name="CVE-2010-0504" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'These issues only affect Mac OS X Server systems.'
</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0505" published="2010-03-30" name="CVE-2010-0505" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 (JPEG2000) image, related to incorrect calculation and the CGImageReadGetBytesAtOffset function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-058" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-058</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510539/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-058: Apple Mac OS X ImageIO Framework JPEG2000 Remote Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0506" published="2010-03-30" name="CVE-2010-0506" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue does not affect Mac OS X v10.6 systems'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0507" published="2010-03-30" name="CVE-2010-0507" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0508" published="2010-03-30" name="CVE-2010-0508" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0509" published="2010-03-30" name="CVE-2010-0509" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0510" published="2010-03-30" name="CVE-2010-0510" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects Mac OS X Server systems'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0511" published="2010-03-30" name="CVE-2010-0511" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritten, which allows attackers to access a workflow via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0512" published="2010-03-30" name="CVE-2010-0512" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects systems configured to use a network account server, and does not affect systems prior to Mac OS X v10.6.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.securityfocus.com/bid/39153" source="BID">39153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0513" published="2010-03-30" name="CVE-2010-0513" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PS Normalizer in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PostScript document.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.apple.com/kb/HT4077

'On Mac OS X v10.6 systems this issue is mitigated by the -fstack-protector compiler flag.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.securityfocus.com/bid/39151" source="BID">39151</ref>
      <ref url="http://osvdb.org/63409" source="OSVDB">63409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0514" published="2010-03-30" name="CVE-2010-0514" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.261 encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7043" source="OVAL">oval:org.mitre.oval:def:7043</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0515" published="2010-03-30" name="CVE-2010-0515" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with H.264 encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6783" source="OVAL">oval:org.mitre.oval:def:6783</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0516" published="2010-03-30" name="CVE-2010-0516" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding, which triggers memory corruption when the length of decompressed data exceeds that of the allocated heap chunk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-040" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-040</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510513/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-040: Apple QuickTime RLE Bit Depth Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7062" source="OVAL">oval:org.mitre.oval:def:7062</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0517" published="2010-03-30" name="CVE-2010-0517" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with M-JPEG encoding, which causes QuickTime to calculate a buffer size using height and width fields, but to use a different field to control the length of a copy operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-037" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-037</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510511/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-037: Apple QuickTime MJPEG Sample Dimensions Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6673" source="OVAL">oval:org.mitre.oval:def:6673</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0518" published="2010-03-30" name="CVE-2010-0518" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with Sorenson encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7077" source="OVAL">oval:org.mitre.oval:def:7077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0519" published="2010-03-30" name="CVE-2010-0519" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-043" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-043</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510519/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-043: Apple QuickTime FlashPix NumberOfTiles Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7498" source="OVAL">oval:org.mitre.oval:def:7498</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0520" published="2010-03-30" name="CVE-2010-0520" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC file, related to crafted DELTA_FLI chunks and untrusted length values in a .fli file, which are not properly handled during decompression.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-044" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-044</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510520/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-044: Apple QuickTime FLI LinePacket Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6801" source="OVAL">oval:org.mitre.oval:def:6801</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0521" published="2010-03-30" name="CVE-2010-0521" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0522" published="2010-03-30" name="CVE-2010-0522" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which allows remote authenticated users to leverage this former membership to obtain a server connection via screen sharing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0523" published="2010-03-30" name="CVE-2010-0523" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified other impact via a crafted file, as demonstrated by a Java applet.</descript>
      <descript source="nvd">Per: http://support.apple.com/kb/HT4077

'This issue only affects Mac OS X Server systems, and does not affect versions 10.6 or later.'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0524" published="2010-03-30" name="CVE-2010-0524" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39234" source="BID">39234</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0525" published="2010-03-30" name="CVE-2010-0525" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certificates for an e-mail recipient, which might make it easier for remote attackers to obtain sensitive information via a brute-force attack on a weakly encrypted e-mail message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0526" published="2010-03-30" name="CVE-2010-0526" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTimeMPEG.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted genl atom in a QuickTime movie file with MPEG encoding, which is not properly handled during decompression.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-045" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-045</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-035" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510530/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-045: Apple QuickTime MPEG-1 genl Atom Remote Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510508/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-035: Apple QuickTime genl Atom Remote Code Execution Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6927" source="OVAL">oval:org.mitre.oval:def:6927</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE">APPLE-SA-2010-03-30-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0527" published="2010-03-31" name="CVE-2010-0527" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html

'This issue does not affect Mac OS X systems'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7458" source="OVAL">oval:org.mitre.oval:def:7458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers prev="1" num="7.6.0" edition="-" />
        <vers prev="1" num="7.6.0" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0528" published="2010-03-31" name="CVE-2010-0528" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html

'This issue does not affect Mac OS X systems.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-042" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-042</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510518/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-042: Apple QuickTime MediaVideo Compressor Name Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6989" source="OVAL">oval:org.mitre.oval:def:6989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers prev="1" num="7.6.0" edition="-" />
        <vers prev="1" num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.6" edition="-" />
        <vers num="7.6.6" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0529" published="2010-03-31" name="CVE-2010-0529" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html

'This issue does not affect Mac OS X systems.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-067" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510569/100/0/threaded" source="BUGTRAQ">20100406 ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6780" source="OVAL">oval:org.mitre.oval:def:6780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers prev="1" num="7.6.0" edition="-" />
        <vers prev="1" num="7.6.0" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0530" published="2010-12-09" name="CVE-2010-0530" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-12-07-1</ref>
      <ref url="http://www.securitytracker.com/id?1024829" source="SECTRACK">1024829</ref>
      <ref url="http://support.apple.com/kb/HT4447" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.2.0" />
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.2.0" />
        <vers num="7.2.1" />
        <vers num="7.3" />
        <vers num="7.3.0" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" />
        <vers num="7.4.1" />
        <vers num="7.4.5" />
        <vers num="7.5.0" />
        <vers num="7.5.5" />
        <vers num="7.6.0" />
        <vers num="7.6.1" />
        <vers num="7.6.2" />
        <vers num="7.6.5" />
        <vers num="7.6.6" />
        <vers num="7.6.7" />
        <vers prev="1" num="7.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0531" published="2010-03-31" name="CVE-2010-0531" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-2</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA" adv="1">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7427" source="OVAL">oval:org.mitre.oval:def:7427</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:mac" />
        <vers num="9.0" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:mac" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:mac" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers num="9.0.2" edition="-:mac" />
        <vers prev="1" num="9.0.3" edition="-" />
        <vers prev="1" num="9.0.3" edition="-:mac" />
        <vers prev="1" num="9.0.3" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0532" published="2010-03-31" name="CVE-2010-0532" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html

'This issue does not affect Mac OS X systems.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-2</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://secunia.com/advisories/39135" source="SECUNIA" adv="1">39135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7110" source="OVAL">oval:org.mitre.oval:def:7110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers prev="1" num="9.0.3" edition="-" />
        <vers prev="1" num="9.0.3" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0533" published="2010-03-30" name="CVE-2010-0533" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AFP Server in Apple Mac OS X before 10.6.3 allows remote attackers to list a share root's parent directory, and read and modify files in that directory, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers prev="1" num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0534" published="2010-03-30" name="CVE-2010-0534" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Wiki Server in Apple Mac OS X 10.6 before 10.6.3 does not enforce the service access control list (SACL) for weblogs during weblog creation, which allows remote authenticated users to publish content via HTTP requests.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0535" published="2010-03-30" name="CVE-2010-0535" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0536" published="2010-03-31" name="CVE-2010-0536" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html

' This issue does not affect Mac OS X systems.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-03-30-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6969" source="OVAL">oval:org.mitre.oval:def:6969</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers prev="1" num="7.6.0" edition="-" />
        <vers prev="1" num="7.6.0" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0537" published="2010-03-30" name="CVE-2010-0537" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0538" published="2010-05-21" name="CVE-2010-0538" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted applet, related to the com.sun.medialib.mlib package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40238" source="BID" patch="1">40238</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://securitytracker.com/id?1024011" source="SECTRACK">1024011</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0539" published="2010-05-21" name="CVE-2010-0539" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted applet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" patch="1" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.securityfocus.com/bid/40240" source="BID" patch="1">40240</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://securitytracker.com/id?1024012" source="SECTRACK">1024012</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="java_1.5">
        <vers num="0" edition="23" />
      </prod>
      <prod vendor="apple" name="java_1.6">
        <vers num="0" edition="17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0540" published="2010-06-17" name="CVE-2010-0540" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" patch="1" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0535" source="VUPEN">ADV-2011-0535</ref>
      <ref url="http://www.securitytracker.com/id?1024122" source="SECTRACK">1024122</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:234" source="MANDRIVA">MDVSA-2010:234</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:233" source="MANDRIVA">MDVSA-2010:233</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:232" source="MANDRIVA">MDVSA-2010:232</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2176" source="DEBIAN">DSA-2176</ref>
      <ref url="http://secunia.com/advisories/43521" source="SECUNIA">43521</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10382" source="OVAL">oval:org.mitre.oval:def:10382</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://cups.org/str.php?L3498" source="CONFIRM">http://cups.org/str.php?L3498</ref>
      <ref url="http://cups.org/articles.php?L596" source="CONFIRM">http://cups.org/articles.php?L596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0541" published="2010-06-17" name="CVE-2010-0541" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0909.html" source="REDHAT">RHSA-2011:0909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0908.html" source="REDHAT">RHSA-2011:0908</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:098" source="MANDRIVA">MDVSA-2011:098</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:097" source="MANDRIVA">MDVSA-2011:097</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0542" published="2010-06-21" name="CVE-2010-0542" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=587746" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=587746</ref>
      <ref url="http://cups.org/strfiles/3516/str3516.patch" source="CONFIRM" patch="1">http://cups.org/strfiles/3516/str3516.patch</ref>
      <ref url="http://cups.org/articles.php?L596" source="CONFIRM" patch="1">http://cups.org/articles.php?L596</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0535" source="VUPEN">ADV-2011-0535</ref>
      <ref url="http://www.securityfocus.com/bid/40943" source="BID">40943</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:234" source="MANDRIVA">MDVSA-2010:234</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:232" source="MANDRIVA">MDVSA-2010:232</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2176" source="DEBIAN">DSA-2176</ref>
      <ref url="http://securitytracker.com/id?1024121" source="SECTRACK">1024121</ref>
      <ref url="http://secunia.com/advisories/43521" source="SECUNIA">43521</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10365" source="OVAL">oval:org.mitre.oval:def:10365</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html" source="SUSE">SUSE-SR:2010:023</ref>
      <ref url="http://cups.org/str.php?L3516" source="CONFIRM">http://cups.org/str.php?L3516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2" edition="b1" />
        <vers num="1.2" edition="b2" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2" edition="rc2" />
        <vers num="1.2" edition="rc3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" edition="b1" />
        <vers num="1.3" edition="rc1" />
        <vers num="1.3" edition="rc2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers prev="1" num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0543" published="2010-06-17" name="CVE-2010-0543" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ImageIO in Apple Mac OS X 10.5.8, and 10.6 before 10.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with MPEG2 encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" patch="1" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0544" published="2010-06-11" name="CVE-2010-0544" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to a malformed URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6656" source="OVAL">oval:org.mitre.oval:def:6656</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0545" published="2010-06-17" name="CVE-2010-0545" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" patch="1" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0546" published="2010-06-17" name="CVE-2010-0546" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" patch="1" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0547" published="2010-02-04" name="CVE-2010-0547" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1062" source="VUPEN">ADV-2010-1062</ref>
      <ref url="http://www.securityfocus.com/bid/38326" source="BID">38326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:090" source="MANDRIVA">MDVSA-2010:090</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054" source="CONFIRM">http://git.samba.org/?p=samba.git;a=commit;h=a065c177dfc8f968775593ba00dffafeebb2e054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="1.9.17" edition="p1" />
        <vers num="1.9.17" edition="p2" />
        <vers num="1.9.17" edition="p3" />
        <vers num="1.9.17" edition="p4" />
        <vers num="1.9.17" edition="p5" />
        <vers num="1.9.18" edition="p1" />
        <vers num="1.9.18" edition="p10" />
        <vers num="1.9.18" edition="p2" />
        <vers num="1.9.18" edition="p3" />
        <vers num="1.9.18" edition="p4" />
        <vers num="1.9.18" edition="p5" />
        <vers num="1.9.18" edition="p6" />
        <vers num="1.9.18" edition="p7" />
        <vers num="1.9.18" edition="p8" />
        <vers num="2.2.0" />
        <vers num="2.2.0a" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.1a" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3a" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.7a" />
        <vers num="2.2.8" />
        <vers num="2.2.8a" />
        <vers num="2.2.9" />
        <vers num="2.2a" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14a" />
        <vers num="3.0.2" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
        <vers num="3.0.24" />
        <vers num="3.0.25" edition="pre1" />
        <vers num="3.0.25" edition="pre2" />
        <vers num="3.0.25" edition="rc1" />
        <vers num="3.0.25" edition="rc2" />
        <vers num="3.0.25" edition="rc3" />
        <vers num="3.0.25a" />
        <vers num="3.0.25b" />
        <vers num="3.0.25c" />
        <vers num="3.0.26" />
        <vers num="3.0.26a" />
        <vers num="3.0.27" />
        <vers num="3.0.27a" />
        <vers num="3.0.28" />
        <vers num="3.0.28a" />
        <vers num="3.0.29" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.30" />
        <vers num="3.0.31" />
        <vers num="3.0.32" />
        <vers num="3.0.33" />
        <vers num="3.0.34" />
        <vers num="3.0.35" />
        <vers num="3.0.36" />
        <vers num="3.0.37" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.10" />
        <vers num="3.2.11" />
        <vers num="3.2.12" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.2.9" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.10" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.3.9" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers prev="1" num="3.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0548" published="2010-02-04" name="CVE-2010-0548" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox authorization or (2) read device configuration information via via unknown vectors that bypass web server authorization.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX10-002_v1.0.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX10-002_v1.0.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0209" source="VUPEN" adv="1">ADV-2010-0209</ref>
      <ref url="http://secunia.com/advisories/38139" source="SECUNIA" adv="1">38139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_5632">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5638">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5645">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5655">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5665">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5675">
        <vers num="" />
      </prod>
      <prod vendor="xerox" name="workcentre_5687">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0549" published="2010-02-04" name="CVE-2010-0549" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure Access Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX10-001_v1.0.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX10-001_v1.0.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0208" source="VUPEN" adv="1">ADV-2010-0208</ref>
      <ref url="http://www.securitytracker.com/id?1023500" source="SECTRACK">1023500</ref>
      <ref url="http://secunia.com/advisories/38339" source="SECUNIA" adv="1">38339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre_6400_net_controller">
        <vers num="060.079.11410" />
        <vers num="060.079.29310" />
      </prod>
      <prod vendor="xerox" name="workcentre_6400_system_software">
        <vers num="060.070.109.11407" />
        <vers num="060.070.109.29510" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0550" published="2010-02-04" name="CVE-2010-0550" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55976" source="XF">gncaster-httpbasic-weak-security(55976)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509199/100/0/threaded" source="BUGTRAQ">20100127 [RT-SA-2010-003] Geo++(R) GNCASTER: Faulty implementation of HTTPDigest Authentication</ref>
      <ref url="http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication" source="MISC">http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication</ref>
      <ref url="http://secunia.com/advisories/38323" source="SECUNIA" adv="1">38323</ref>
      <ref url="http://osvdb.org/62013" source="OSVDB">62013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geopp" name="geo++_gncaster">
        <vers num="1.4.0.0" />
        <vers prev="1" num="1.4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0551" published="2010-02-04" name="CVE-2010-0551" modified="2011-01-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication attempt, which includes sensitive memory in the response.  NOTE: this is referred to as a "memory leak" by some sources, but is better characterized as "memory disclosure."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55978" source="XF">gncaster-server-info-disclosure(55978)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509199/100/0/threaded" source="BUGTRAQ">20100127 [RT-SA-2010-003] Geo++(R) GNCASTER: Faulty implementation of HTTPDigest Authentication</ref>
      <ref url="http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication" source="MISC">http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication</ref>
      <ref url="http://secunia.com/advisories/38323" source="SECUNIA" adv="1">38323</ref>
      <ref url="http://osvdb.org/62015" source="OSVDB">62015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geopp" name="geo++_gncaster">
        <vers num="1.4.0.0" />
        <vers prev="1" num="1.4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0552" published="2010-02-04" name="CVE-2010-0552" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55974" source="XF">gncaster-httpget-code-execution(55974)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509194/100/0/threaded" source="BUGTRAQ">20100127 [RT-SA-2010-001] Geo++(R) GNCASTER: Insecure handling of long URLs</ref>
      <ref url="http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-001/-geo-r-gncaster-insecure-handling-of-long-urls" source="MISC">http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-001/-geo-r-gncaster-insecure-handling-of-long-urls</ref>
      <ref url="http://secunia.com/advisories/38323" source="SECUNIA" adv="1">38323</ref>
      <ref url="http://osvdb.org/62011" source="OSVDB">62011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geopp" name="geo++_gncaster">
        <vers num="1.4.0.0" />
        <vers prev="1" num="1.4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0553" published="2010-02-04" name="CVE-2010-0553" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55975" source="XF">gncaster-nmea-code-execution(55975)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509197/100/0/threaded" source="BUGTRAQ">20100127 [RT-SA-2010-002] Geo++(R) GNCASTER: Insecure handling of NMEA-data</ref>
      <ref url="http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-002/-geo-r-gncaster-insecure-handling-of-nmea-data" source="MISC">http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-002/-geo-r-gncaster-insecure-handling-of-nmea-data</ref>
      <ref url="http://secunia.com/advisories/38323" source="SECUNIA" adv="1">38323</ref>
      <ref url="http://osvdb.org/62012" source="OSVDB">62012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geopp" name="geo++_gncaster">
        <vers num="1.4.0.0" />
        <vers prev="1" num="1.4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0554" published="2010-02-04" name="CVE-2010-0554" modified="2010-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55977" source="XF">gncaster-nonce-replay(55977)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509199/100/0/threaded" source="BUGTRAQ">20100127 [RT-SA-2010-003] Geo++(R) GNCASTER: Faulty implementation of HTTPDigest Authentication</ref>
      <ref url="http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication" source="MISC">http://www.redteam-pentesting.de/en/advisories/rt-sa-2010-003/-geo-r-gncaster-faulty-implementation-of-http-digest-authentication</ref>
      <ref url="http://secunia.com/advisories/38323" source="SECUNIA" adv="1">38323</ref>
      <ref url="http://osvdb.org/62014" source="OSVDB">62014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geopp" name="geo++_gncaster">
        <vers num="1.4.0.0" />
        <vers prev="1" num="1.4.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0555" published="2010-02-04" name="CVE-2010-0555" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38056" source="BID">38056</ref>
      <ref url="http://www.securityfocus.com/bid/38055" source="BID">38055</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509345/100/0/threaded" source="BUGTRAQ">20100203 CORE-2009-0625: Internet Explorer Dynamic OBJECT tag and URLMON sniffing vulnerabilities</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/980088.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/980088.mspx</ref>
      <ref url="http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag" source="MISC">http://www.coresecurity.com/content/internet-explorer-dynamic-object-tag</ref>
      <ref url="http://osvdb.org/62157" source="OSVDB">62157</ref>
      <ref url="http://isc.sans.org/diary.html?n&amp;storyid=8152" source="MISC">http://isc.sans.org/diary.html?n&amp;storyid=8152</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/02/03/security-advisory-980088-released.aspx" source="MISC">http://blogs.technet.com/msrc/archive/2010/02/03/security-advisory-980088-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0556" published="2010-02-18" name="CVE-2010-0556" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56216" source="XF">googlechrome-dialogs-phishing(56216)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.vsecurity.com/advisory/20100215-1.txt" source="MISC">http://www.vsecurity.com/advisory/20100215-1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509543/100/0/threaded" source="BUGTRAQ">20100216 Chrome Password Manager Cross Origin Weakness (CVE-2010-0556)</ref>
      <ref url="http://www.osvdb.org/62319" source="OSVDB">62319</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14407" source="OVAL">oval:org.mitre.oval:def:14407</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=32718" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=32718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0557" published="2010-02-05" name="CVE-2010-0557" modified="2010-02-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0297" source="VUPEN" adv="1">ADV-2010-0297</ref>
      <ref url="http://www.securityfocus.com/bid/38084" source="BID">38084</ref>
      <ref url="http://www.osvdb.org/62118" source="OSVDB">62118</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21419179" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21419179</ref>
      <ref url="http://secunia.com/advisories/38457" source="SECUNIA" adv="1">38457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_express">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0558" published="2010-02-05" name="CVE-2010-0558" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56521" source="XF">opensolaris-smbadm-unspecified(56521)</ref>
      <ref url="http://www.securitytracker.com/id?1023545" source="SECTRACK">1023545</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-275790-1" source="SUNALERT" adv="1">275790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":x86" />
        <vers num="snv_111" edition=":sparc" />
        <vers num="snv_112" edition="" />
        <vers num="snv_112" edition=":x86" />
        <vers num="snv_113" edition="" />
        <vers num="snv_113" edition=":sparc" />
        <vers num="snv_113" edition=":x86" />
        <vers num="snv_114" edition="" />
        <vers num="snv_114" edition=":x86" />
        <vers num="snv_115" edition="" />
        <vers num="snv_115" edition=":sparc" />
        <vers num="snv_115" edition=":x86" />
        <vers num="snv_116" edition="" />
        <vers num="snv_116" edition=":x86" />
        <vers num="snv_117" edition="" />
        <vers num="snv_117" edition=":x86" />
        <vers num="snv_117" edition=":sparc" />
        <vers num="snv_118" edition="" />
        <vers num="snv_118" edition=":x86" />
        <vers num="snv_119" edition="" />
        <vers num="snv_119" edition=":x86" />
        <vers num="snv_119" edition=":sparc" />
        <vers num="snv_120" edition="" />
        <vers num="snv_120" edition=":sparc" />
        <vers num="snv_120" edition=":x86" />
        <vers num="snv_121" edition="" />
        <vers num="snv_121" edition=":x86" />
        <vers num="snv_121" edition=":sparc" />
        <vers num="snv_122" edition="" />
        <vers num="snv_122" edition=":sparc" />
        <vers num="snv_122" edition=":x86" />
        <vers num="snv_123" edition="" />
        <vers num="snv_123" edition=":sparc" />
        <vers num="snv_124" edition="" />
        <vers num="snv_124" edition=":sparc" />
        <vers num="snv_124" edition=":x86" />
        <vers num="snv_125" edition="" />
        <vers num="snv_125" edition=":x86" />
        <vers num="snv_125" edition=":sparc" />
        <vers num="snv_126" edition="" />
        <vers num="snv_126" edition=":sparc" />
        <vers num="snv_126" edition=":x86" />
        <vers num="snv_127" edition="" />
        <vers num="snv_127" edition=":x86" />
        <vers num="snv_127" edition=":sparc" />
        <vers num="snv_128" edition="" />
        <vers num="snv_128" edition=":x86" />
        <vers num="snv_129" edition="" />
        <vers num="snv_129" edition=":x86" />
        <vers num="snv_129" edition=":sparc" />
        <vers num="snv_130" edition="" />
        <vers num="snv_130" edition=":sparc" />
        <vers num="snv_130" edition=":x86" />
        <vers num="snv_131" edition="" />
        <vers num="snv_131" edition=":sparc" />
        <vers num="snv_131" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0559" published="2010-02-05" name="CVE-2010-0559" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1023545" source="SECTRACK">1023545</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021793.1-1" source="SUNALERT">1021793</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-275790-1" source="SUNALERT" adv="1">275790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":x86" />
        <vers num="snv_111" edition=":sparc" />
        <vers num="snv_112" edition="" />
        <vers num="snv_112" edition=":x86" />
        <vers num="snv_112" edition=":sparc" />
        <vers num="snv_113" edition="" />
        <vers num="snv_113" edition=":sparc" />
        <vers num="snv_113" edition=":x86" />
        <vers num="snv_114" edition="" />
        <vers num="snv_114" edition=":x86" />
        <vers num="snv_114" edition=":sparc" />
        <vers num="snv_115" edition="" />
        <vers num="snv_115" edition=":sparc" />
        <vers num="snv_115" edition=":x86" />
        <vers num="snv_116" edition="" />
        <vers num="snv_116" edition=":x86" />
        <vers num="snv_116" edition=":sparc" />
        <vers num="snv_117" edition="" />
        <vers num="snv_117" edition=":x86" />
        <vers num="snv_117" edition=":sparc" />
        <vers num="snv_118" edition="" />
        <vers num="snv_118" edition=":sparc" />
        <vers num="snv_118" edition=":x86" />
        <vers num="snv_119" edition="" />
        <vers num="snv_119" edition=":x86" />
        <vers num="snv_119" edition=":sparc" />
        <vers num="snv_120" edition="" />
        <vers num="snv_120" edition=":sparc" />
        <vers num="snv_120" edition=":x86" />
        <vers num="snv_121" edition="" />
        <vers num="snv_121" edition=":x86" />
        <vers num="snv_121" edition=":sparc" />
        <vers num="snv_122" edition="" />
        <vers num="snv_122" edition=":sparc" />
        <vers num="snv_122" edition=":x86" />
        <vers num="snv_123" edition="" />
        <vers num="snv_123" edition=":sparc" />
        <vers num="snv_124" edition="" />
        <vers num="snv_124" edition=":sparc" />
        <vers num="snv_124" edition=":x86" />
        <vers num="snv_125" edition="" />
        <vers num="snv_125" edition=":sparc" />
        <vers num="snv_125" edition=":x86" />
        <vers num="snv_126" edition="" />
        <vers num="snv_126" edition=":x86" />
        <vers num="snv_126" edition=":sparc" />
        <vers num="snv_127" edition="" />
        <vers num="snv_127" edition=":sparc" />
        <vers num="snv_128" edition="" />
        <vers num="snv_128" edition=":x86" />
        <vers num="snv_128" edition=":sparc" />
        <vers num="snv_129" edition="" />
        <vers num="snv_129" edition=":x86" />
        <vers num="snv_129" edition=":sparc" />
        <vers num="snv_130" edition="" />
        <vers num="snv_130" edition=":sparc" />
        <vers num="snv_131" edition="" />
        <vers num="snv_131" edition=":sparc" />
        <vers num="snv_131" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0560" published="2010-02-08" name="CVE-2010-0560" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BIOS in Intel Desktop Board DB, DG, DH, DP, and DQ Series allows local administrators to execute arbitrary code in System Management Mode (SSM) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56384" source="XF">intel-bios-privilege-escalation(56384)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0271" source="VUPEN" adv="1">ADV-2010-0271</ref>
      <ref url="http://www.securityfocus.com/bid/38251" source="BID">38251</ref>
      <ref url="http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00022&amp;languageid=en-fr" source="CONFIRM" adv="1">http://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00022&amp;languageid=en-fr</ref>
      <ref url="http://secunia.com/advisories/38413" source="SECUNIA" adv="1">38413</ref>
      <ref url="http://osvdb.org/62071" source="OSVDB">62071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="intel_desktop_board">
        <vers num="db" />
        <vers num="dg" />
        <vers num="dh" />
        <vers num="dp" />
        <vers num="dq" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0561" published="2010-02-08" name="CVE-2010-0561" modified="2010-02-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-21 allows local users to cause a denial of service (kernel panic) via a negative mixer index number being passed to (1) the azalia_query_devinfo function in the azalia audio driver (src/sys/dev/pci/azalia.c) or (2) the hdaudio_afg_query_devinfo function in the hdaudio audio driver (src/sys/dev/pci/hdaudio/hdaudio_afg.c).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1023539" source="SECTRACK">1023539</ref>
      <ref url="http://www.securityfocus.com/bid/38057" source="BID">38057</ref>
      <ref url="http://secunia.com/advisories/38284" source="SECUNIA" adv="1">38284</ref>
      <ref url="http://osvdb.org/62082" source="OSVDB">62082</ref>
      <ref url="http://osvdb.org/62081" source="OSVDB">62081</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-003.txt.asc" source="NETBSD" adv="1">NetBSD-SA2010-003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="4.0" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0562" published="2010-02-08" name="CVE-2010-0562" modified="2011-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0296" source="VUPEN" adv="1">ADV-2010-0296</ref>
      <ref url="http://www.securitytracker.com/id?1023543" source="SECTRACK">1023543</ref>
      <ref url="http://www.securityfocus.com/bid/38088" source="BID">38088</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:037" source="MANDRIVA">MDVSA-2010:037</ref>
      <ref url="http://www.fetchmail.info/fetchmail-SA-2010-01.txt" source="CONFIRM" adv="1">http://www.fetchmail.info/fetchmail-SA-2010-01.txt</ref>
      <ref url="http://secunia.com/advisories/38391" source="SECUNIA" adv="1">38391</ref>
      <ref url="http://osvdb.org/62114" source="OSVDB">62114</ref>
      <ref url="http://mknod.org/svn/fetchmail/branches/BRANCH_6-3/fetchmail-SA-2010-01.txt" source="CONFIRM">http://mknod.org/svn/fetchmail/branches/BRANCH_6-3/fetchmail-SA-2010-01.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="6.3.11" />
        <vers num="6.3.12" />
        <vers num="6.3.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0563" published="2010-02-08" name="CVE-2010-0563" modified="2010-11-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Single Sign-on (SSO) functionality in IBM WebSphere Application Server (WAS) 7.0.0.0 through 7.0.0.8 does not recognize the Requires SSL configuration option, which might allow remote attackers to obtain sensitive information by sniffing network sessions that were expected to be encrypted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21417839" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21417839</ref>
      <ref url="http://www.securityfocus.com/bid/38122" source="BID">38122</ref>
      <ref url="http://www.osvdb.org/62140" source="OSVDB">62140</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PM00610" source="AIXAPAR">PM00610</ref>
      <ref url="http://securitytracker.com/id?1023551" source="SECTRACK">1023551</ref>
      <ref url="http://secunia.com/advisories/38425" source="SECUNIA" adv="1">38425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0564" published="2010-02-09" name="CVE-2010-0564" modified="2010-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029, allows attackers to cause a denial of service (crash or OfficeScan hang) via unspecified vectors.  NOTE: it is likely that this issue also affects tmufeng.dll before 2.0.0.1049 for OfficeScan 10.0.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0295" source="VUPEN" patch="1" adv="1">ADV-2010-0295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56097" source="XF">officescan-tmufe-bo(56097)</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/readme_1224.txt" source="MISC">http://www.trendmicro.com/ftp/documentation/readme/readme_1224.txt</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/OSCE_80_Win_SP1_Patch_5_en_readme.txt" source="CONFIRM">http://www.trendmicro.com/ftp/documentation/readme/OSCE_80_Win_SP1_Patch_5_en_readme.txt</ref>
      <ref url="http://www.securitytracker.com/id?1023553" source="SECTRACK">1023553</ref>
      <ref url="http://www.securityfocus.com/bid/38083" source="BID">38083</ref>
      <ref url="http://secunia.com/advisories/38396" source="SECUNIA" adv="1">38396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trendmicro" name="officescan">
        <vers prev="1" num="8.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0565" published="2010-02-19" name="CVE-2010-0565" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10), allows remote attackers to cause a denial of service (page fault and device reload) via a malformed DTLS message, aka Bug ID CSCtb64913 and "WebVPN DTLS Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56339" source="XF">cisco-asa-webvpn-dtls-dos(56339)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38280" source="BID">38280</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA">38618</ref>
      <ref url="http://osvdb.org/62430" source="OSVDB">62430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0566" published="2010-02-19" name="CVE-2010-0566" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10) allows remote attackers to cause a denial of service (device reload) via a malformed TCP segment when certain NAT translation and Cisco AIP-SSM configurations are used, aka Bug ID CSCtb37219.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56340" source="XF">cisco-asa-nat-aipssm-dos(56340)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38278" source="BID">38278</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62431" source="OSVDB">62431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0567" published="2010-02-19" name="CVE-2010-0567" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (active IPsec tunnel loss and prevention of new tunnels) via a malformed IKE message through an existing tunnel to UDP port 4500, aka Bug ID CSCtc47782.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56341" source="XF">cisco-asa-ike-dos(56341)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38279" source="BID">38279</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38636" source="SECUNIA" adv="1">38636</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62436" source="OSVDB">62436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0568" published="2010-02-19" name="CVE-2010-0568" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.7), 8.1 before 8.1(2.40), and 8.2 before 8.2(2.1); and Cisco PIX 500 Series Security Appliance; allows remote attackers to bypass NTLMv1 authentication via a crafted username, aka Bug ID CSCte21953.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56342" source="XF">cisco-asa-ntlmv1-security-bypass(56342)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38279" source="BID">38279</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38636" source="SECUNIA" adv="1">38636</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62437" source="OSVDB">62437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0569" published="2010-02-19" name="CVE-2010-0569" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCtc96018.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56337" source="XF">cisco-asa-sip-dos(56337)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0415" source="VUPEN" adv="1">ADV-2010-0415</ref>
      <ref url="http://www.securitytracker.com/id?1023612" source="SECTRACK">1023612</ref>
      <ref url="http://www.securityfocus.com/bid/38281" source="BID">38281</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910c.shtml" source="CISCO" adv="1">20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/38636" source="SECUNIA" adv="1">38636</ref>
      <ref url="http://secunia.com/advisories/38618" source="SECUNIA" adv="1">38618</ref>
      <ref url="http://osvdb.org/62435" source="OSVDB">62435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="asa_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.2" />
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0570" published="2010-03-05" name="CVE-2010-0570" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote attackers to execute arbitrary code via a crafted web application, aka Bug ID CSCta03378.</descript>
      <descript source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml

"Default Credentials

Cisco DMM versions 5.0.x and 5.1.x are affected by this vulnerability. Cisco DMM versions 4.x are not vulnerable"</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml" source="CISCO" patch="1" adv="1">20100303 Multiple Vulnerabilities in Cisco Digital Media Manager</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56634" source="XF">cisco-ddm-default-credentials(56634)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0531" source="VUPEN">ADV-2010-0531</ref>
      <ref url="http://www.securityfocus.com/bid/38503" source="BID">38503</ref>
      <ref url="http://securitytracker.com/id?1023671" source="SECTRACK">1023671</ref>
      <ref url="http://secunia.com/advisories/38800" source="SECUNIA">38800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="digital_media_manager">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0571" published="2010-03-05" name="CVE-2010-0571" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml" source="CISCO" patch="1" adv="1">20100303 Multiple Vulnerabilities in Cisco Digital Media Manager</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56636" source="XF">cisco-ddm-privilege-escalation(56636)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0531" source="VUPEN">ADV-2010-0531</ref>
      <ref url="http://www.securityfocus.com/bid/38500" source="BID">38500</ref>
      <ref url="http://securitytracker.com/id?1023671" source="SECTRACK">1023671</ref>
      <ref url="http://secunia.com/advisories/38800" source="SECUNIA">38800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="digital_media_manager">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0572" published="2010-03-05" name="CVE-2010-0572" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml" source="CISCO" patch="1" adv="1">20100303 Multiple Vulnerabilities in Cisco Digital Media Manager</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56637" source="XF">cisco-ddm-mediaplayer-info-disc(56637)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0531" source="VUPEN">ADV-2010-0531</ref>
      <ref url="http://www.securityfocus.com/bid/38502" source="BID">38502</ref>
      <ref url="http://securitytracker.com/id?1023671" source="SECTRACK">1023671</ref>
      <ref url="http://secunia.com/advisories/38800" source="SECUNIA">38800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="digital_media_manager">
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers prev="1" num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0573" published="2010-03-05" name="CVE-2010-0573" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:C)" CVSS_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability on the Cisco Digital Media Player before 5.2 allows remote attackers to hijack the source of (1) video or (2) data for a display via unknown vectors, related to a "content injection" issue, aka Bug ID CSCtc46024.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b925.shtml

" Vulnerable Products

Cisco Digital Media Player versions earlier than 5.2 are affected by this vulnerability"</impact>
    </impacts>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b925.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56639" source="XF">cisco-mediaplayer-content-data-manipulation(56639)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0532" source="VUPEN">ADV-2010-0532</ref>
      <ref url="http://www.securityfocus.com/bid/38504" source="BID">38504</ref>
      <ref url="http://securitytracker.com/id?1023672" source="SECTRACK">1023672</ref>
      <ref url="http://secunia.com/advisories/38799" source="SECUNIA">38799</ref>
      <ref url="http://osvdb.org/62723" source="OSVDB">62723</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="digital_media_player">
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="digital_media_player_4300g">
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="digital_media_player_4305g">
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="digital_media_player_4400g">
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0574" published="2010-09-10" name="CVE-2010-0574" modified="2010-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 3.2 before 3.2.215.0; 4.1 and 4.2 before 4.2.205.0; 4.1M and 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.188.0; and 5.2 before 5.2.193.11 allows remote attackers to cause a denial of service (device reload) via a crafted IKE packet, aka Bug ID CSCta56653.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b466e9.shtml" source="CISCO" patch="1" adv="1">20100908 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=21287" source="CONFIRM" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=21287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="3.2" />
        <vers num="3.2.116.21" />
        <vers num="3.2.150.10" />
        <vers num="3.2.150.6" />
        <vers num="3.2.171.5" />
        <vers num="3.2.171.6" />
        <vers num="3.2.185.0" />
        <vers num="3.2.193.5" />
        <vers num="3.2.195.10" />
        <vers num="3.2.78.0" />
        <vers num="4.0.108" />
        <vers num="4.0.155.0" />
        <vers num="4.0.155.5" />
        <vers num="4.0.179.11" />
        <vers num="4.0.179.8" />
        <vers num="4.0.196" />
        <vers num="4.0.206.0" />
        <vers num="4.0.217.0" />
        <vers num="4.0.219.0" />
        <vers num="4.1" />
        <vers num="4.1.171.0" />
        <vers num="4.1.181.0" />
        <vers num="4.1.185.0" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="4.2.112.0" />
        <vers num="4.2.117.0" />
        <vers num="4.2.130.0" />
        <vers num="4.2.173.0" />
        <vers num="4.2.174.0" />
        <vers num="4.2.176.0" />
        <vers num="4.2.182.0" />
        <vers num="4.2.61.0" />
        <vers num="4.2.99.0" />
        <vers num="4.2m" />
        <vers num="5.0.148.0" />
        <vers num="5.0.148.2" />
        <vers num="5.1" />
        <vers num="5.1.151.0" />
        <vers num="5.1.152.0" />
        <vers num="5.1.160.0" />
        <vers num="5.2" />
        <vers num="5.2.157.0" />
        <vers num="5.2.169.0" />
        <vers num="6.0" />
        <vers num="6.0.182.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0575" published="2010-09-10" name="CVE-2010-0575" modified="2010-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-3034.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b466e9.shtml" source="CISCO" patch="1" adv="1">20100908 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=21291" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=21291</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wireless_lan_controller_software">
        <vers num="4.2" />
        <vers num="4.2.112.0" />
        <vers num="4.2.117.0" />
        <vers num="4.2.130.0" />
        <vers num="4.2.173.0" />
        <vers num="4.2.174.0" />
        <vers num="4.2.176.0" />
        <vers num="4.2.182.0" />
        <vers num="4.2.61.0" />
        <vers num="4.2.99.0" />
        <vers num="5.0.148.0" />
        <vers num="5.0.148.2" />
        <vers num="5.1" />
        <vers num="5.1.151.0" />
        <vers num="5.1.152.0" />
        <vers num="5.1.160.0" />
        <vers num="6.0" />
        <vers num="6.0.182.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0576" published="2010-03-25" name="CVE-2010-0576" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a crafted LDP packet, aka Bug IDs CSCsz45567 and CSCsj25893.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee2.shtml

'Affected Products

Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software devices are vulnerable if they are configured to listen for either targeted LDP hello messages or link LDP hello messages.

All versions of Cisco IOS Software and Cisco IOS XE Software that support MPLS are affected. Cisco IOS XR Software is affected in releases prior to 3.5.2.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee2.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software Multiprotocol Label Switching Packet Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57143" source="XF">ciscoios-ldp-dos(57143)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0707" source="VUPEN">ADV-2010-0707</ref>
      <ref url="http://www.securitytracker.com/id?1023740" source="SECTRACK">1023740</ref>
      <ref url="http://www.securityfocus.com/bid/38938" source="BID">38938</ref>
      <ref url="http://secunia.com/advisories/39065" source="SECUNIA">39065</ref>
      <ref url="http://osvdb.org/63188" source="OSVDB">63188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0s" />
        <vers num="12.0sl" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.1ax" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1xv" />
        <vers num="12.1yb" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ira" />
        <vers num="12.2irb" />
        <vers num="12.2irc" />
        <vers num="12.2ird" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ixh" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2scb" />
        <vers num="12.2scc" />
        <vers num="12.2se" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2so" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2srd" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sxh" />
        <vers num="12.2sxi" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xn" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2yd" />
        <vers num="12.2yj" />
        <vers num="12.2yn" />
        <vers num="12.2yp" />
        <vers num="12.2yt" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zj" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3t" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xl" />
        <vers num="12.3xr" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xz" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yk" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jdc" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
      </prod>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.4" />
        <vers num="3.2.50" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0577" published="2010-03-25" name="CVE-2010-0577" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (infinite loop, and device reload or hang) via a TCP segment with crafted options, aka Bug ID CSCsz75186.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f34.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software Crafted TCP Packet Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57129" source="XF">ciscoios-tcpsegment-dos(57129)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0703" source="VUPEN">ADV-2010-0703</ref>
      <ref url="http://www.securitytracker.com/id?1023743" source="SECTRACK">1023743</ref>
      <ref url="http://www.securityfocus.com/bid/38930" source="BID">38930</ref>
      <ref url="http://secunia.com/advisories/39078" source="SECUNIA">39078</ref>
      <ref url="http://osvdb.org/63178" source="OSVDB">63178</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2jx" />
        <vers num="12.2mc" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xr" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yd" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yy" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jec" />
        <vers num="12.3jed" />
        <vers num="12.3jk" />
        <vers num="12.3jl" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jdc" />
        <vers num="12.4jdd" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0578" published="2010-03-25" name="CVE-2010-0578" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service (device reload) via a malformed IKE packet, aka Bug ID CSCtb13491.</descript>
      <descript source="nvd">Per:http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee5.shtml

'IPsec is an IP security feature that provides robust authentication and encryption of IP packets. IKE is a key management protocol standard that is used with the IPsec standard.

IKE is a hybrid protocol that implements the Oakley and SKEME key exchanges inside the Internet Security Association and Key Management Protocol (ISAKMP) framework. (ISAKMP, Oakley, and SKEME are security protocols that are implemented by IKE.). More information on IKE is available at the following link:

http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/sec_key_exch_ipsec.html

A vulnerability exists in the Cisco IOS Software implementation of IKE where a malformed packet may cause a device running Cisco IOS Software to reload. Only Cisco 7200 Series and Cisco 7301 routers running Cisco IOS software with a VPN Acceleration Module 2+ (VAM2+) installed are affected.

This vulnerability is documented in Cisco Bug ID CSCtb13491 ( registered customers only) and has been assigned CVE ID CVE-2010-0578.'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee5.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software IPsec Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57148" source="XF">ciscoios-vpn-dos(57148)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0709" source="VUPEN">ADV-2010-0709</ref>
      <ref url="http://www.securitytracker.com/id?1023741" source="SECTRACK">1023741</ref>
      <ref url="http://www.securityfocus.com/bid/38932" source="BID">38932</ref>
      <ref url="http://secunia.com/advisories/39057" source="SECUNIA">39057</ref>
      <ref url="http://osvdb.org/63182" source="OSVDB">63182</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2sb" />
        <vers num="12.2sca" />
        <vers num="12.2scb" />
        <vers num="12.2scc" />
        <vers num="12.2sra" />
        <vers num="12.3t" />
        <vers num="12.3xe" />
        <vers num="12.3xj" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jdc" />
        <vers num="12.4jdd" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0579" published="2010-03-25" name="CVE-2010-0579" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device reload) via a malformed SIP message, aka Bug ID CSCtb93416, the "SIP Message Handling Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20063" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20063</ref>
      <ref url="http://securitytracker.com/id?1023744" source="SECTRACK">1023744</ref>
      <ref url="http://secunia.com/advisories/39068" source="SECUNIA">39068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3jk" />
        <vers num="12.3t" />
        <vers num="12.3xd" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xd" />
        <vers num="12.4xp" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0580" published="2010-03-25" name="CVE-2010-0580" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20064" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20064</ref>
      <ref url="http://securitytracker.com/id?1023744" source="SECTRACK">1023744</ref>
      <ref url="http://secunia.com/advisories/39068" source="SECUNIA">39068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3jk" />
        <vers num="12.3t" />
        <vers num="12.3xd" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xd" />
        <vers num="12.4xp" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0581" published="2010-03-25" name="CVE-2010-0581" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20065" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20065</ref>
      <ref url="http://securitytracker.com/id?1023744" source="SECTRACK">1023744</ref>
      <ref url="http://secunia.com/advisories/39068" source="SECUNIA">39068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3jk" />
        <vers num="12.3t" />
        <vers num="12.3xd" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xd" />
        <vers num="12.4xp" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0582" published="2010-03-25" name="CVE-2010-0582" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (interface queue wedge) via malformed H.323 packets, aka Bug ID CSCta19962.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee4.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software H.323 Denial of Service Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0706" source="VUPEN">ADV-2010-0706</ref>
      <ref url="http://www.securitytracker.com/id?1023742" source="SECTRACK">1023742</ref>
      <ref url="http://secunia.com/advisories/39067" source="SECUNIA">39067</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1xu" />
        <vers num="12.1yd" />
        <vers num="12.2b" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2cz" />
        <vers num="12.2mc" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xq" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2yf" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yy" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3t" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xj" />
        <vers num="12.4xl" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="15.0m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0583" published="2010-03-25" name="CVE-2010-0583" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee4.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco IOS Software H.323 Denial of Service Vulnerabilities</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57140" source="XF">ciscoios-memory-dos(57140)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0706" source="VUPEN">ADV-2010-0706</ref>
      <ref url="http://www.securitytracker.com/id?1023742" source="SECTRACK">1023742</ref>
      <ref url="http://www.securityfocus.com/bid/38934" source="BID">38934</ref>
      <ref url="http://secunia.com/advisories/39067" source="SECUNIA">39067</ref>
      <ref url="http://osvdb.org/63181" source="OSVDB">63181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1xu" />
        <vers num="12.1yd" />
        <vers num="12.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0584" published="2010-03-25" name="CVE-2010-0584" modified="2010-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.4, when NAT SCCP fragmentation support is enabled, allows remote attackers to cause a denial of service (device reload) via crafted Skinny Client Control Protocol (SCCP) packets, aka Bug ID CSCsy09250.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0708" source="VUPEN">ADV-2010-0708</ref>
      <ref url="http://www.securitytracker.com/id?1023739" source="SECTRACK">1023739</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20ee6.shtml" source="CISCO" adv="1">20100324 Cisco IOS Software NAT Skinny Call Control Protocol Vulnerability</ref>
      <ref url="http://secunia.com/advisories/39062" source="SECUNIA">39062</ref>
      <ref url="http://osvdb.org/63187" source="OSVDB">63187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4gc" />
        <vers num="12.4md" />
        <vers num="12.4mda" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
        <vers num="12.4yd" />
        <vers num="12.4ye" />
        <vers num="12.4yg" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0585" published="2010-03-25" name="CVE-2010-0585" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz48614, the "SCCP Packet Processing Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f33.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco Unified Communications Manager Express Denial of Service Vulnerabilities</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20069" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20069</ref>
      <ref url="http://secunia.com/advisories/39069" source="SECUNIA">39069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yi" />
        <vers num="12.2b" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2mc" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xb" />
        <vers num="12.2xg" />
        <vers num="12.2xm" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yy" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3jk" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0586" published="2010-03-25" name="CVE-2010-0586" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz49741, the "SCCP Request Handling Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f33.shtml" source="CISCO" patch="1" adv="1">20100324 Cisco Unified Communications Manager Express Denial of Service Vulnerabilities</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20070" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20070</ref>
      <ref url="http://secunia.com/advisories/39069" source="SECUNIA">39069</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6625" source="OVAL">oval:org.mitre.oval:def:6625</ref>
      <ref url="http://osvdb.org/63177" source="OSVDB">63177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yi" />
        <vers num="12.2b" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2mc" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xb" />
        <vers num="12.2xg" />
        <vers num="12.2xm" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yy" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3jk" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.3za" />
        <vers num="12.4" />
        <vers num="12.4gc" />
        <vers num="12.4mr" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
        <vers num="12.4yb" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0587" published="2010-03-05" name="CVE-2010-0587" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per:http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml

The following products are affected by vulnerabilities that are described in this advisory:

    * Cisco Unified Communications Manager 4.x
    * Cisco Unified Communications Manager 5.x
    * Cisco Unified Communications Manager 6.x
    * Cisco Unified Communications Manager 7.x</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Unified Communications Manager Denial of Service Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38496" source="BID">38496</ref>
      <ref url="http://securitytracker.com/id?1023670" source="SECTRACK">1023670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="4.1" edition="(3)sr.5" />
        <vers num="4.1" edition="(3)sr4" />
        <vers num="4.1" edition="(3)sr5" />
        <vers num="4.1" edition="(3)sr5b" />
        <vers num="4.1" edition="(3)sr5c" />
        <vers num="4.1(3)" />
        <vers num="4.1(3)sr1" />
        <vers num="4.1(3)sr2" />
        <vers num="4.1(3)sr3" />
        <vers num="4.1(3)sr4" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.2" edition="4.2(3)sr.2" />
        <vers num="4.2" edition="4.2_(3)sr2b" />
        <vers num="4.2" edition="4.2_(3)sr3" />
        <vers num="4.2(3)sr1" />
        <vers num="4.2(3)sr2b" />
        <vers num="4.2(3)sr3" />
        <vers num="4.2(3)sr4" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.3_sr3" />
        <vers num="4.2.3sr1" />
        <vers num="4.2.3sr2" />
        <vers num="4.2.3sr2b" />
        <vers num="4.2_1" />
        <vers num="4.2_2" />
        <vers num="4.2_3" />
        <vers num="4.2_3sr1" />
        <vers num="4.3" edition="4.3(1)sr.1" />
        <vers num="4.3(1)" />
        <vers num="4.3(1)sr.1" />
        <vers num="4.3(2)" />
        <vers num="4.3(2)sr1" />
        <vers num="4.3.1" />
        <vers num="4.3_1" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(1a)" />
        <vers num="6.1" edition="(1a)" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(1b)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2)su1" />
        <vers num="6.1(2)su1a" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1.0" />
        <vers num="7.0" />
        <vers num="7.0(1)" />
        <vers num="7.0(2)" />
        <vers num="7.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0588" published="2010-03-05" name="CVE-2010-0588" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdStatReq message with an invalid Line number, aka Bug ID CSCtc47823.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Unified Communications Manager Denial of Service Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38501" source="BID">38501</ref>
      <ref url="http://securitytracker.com/id?1023670" source="SECTRACK">1023670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(1a)" />
        <vers num="6.1" edition="(1a)" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(1b)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2)su1" />
        <vers num="6.1(2)su1a" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1.0" />
        <vers num="7.0" />
        <vers num="7.0(1)" />
        <vers num="7.0(2)" />
        <vers num="7.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0589" published="2010-04-15" name="CVE-2010-0589" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtml" source="CISCO" patch="1" adv="1">20100414 Cisco Secure Desktop ActiveX Control Code Execution Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57812" source="XF">cisco-csdwebinstaller-code-execution(57812)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-072/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-072/</ref>
      <ref url="http://www.securityfocus.com/bid/39478" source="BID">39478</ref>
      <ref url="http://securitytracker.com/id?1023881" source="SECTRACK">1023881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="secure_desktop">
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1.27" />
        <vers num="3.1.1.33" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.2048" />
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0590" published="2010-03-05" name="CVE-2010-0590" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Unified Communications Manager Denial of Service Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38495" source="BID">38495</ref>
      <ref url="http://securitytracker.com/id?1023670" source="SECTRACK">1023670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="7.0" />
        <vers num="7.0(1)" />
        <vers num="7.0(2)" />
        <vers num="7.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0591" published="2010-03-05" name="CVE-2010-0591" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Unified Communications Manager Denial of Service Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38498" source="BID">38498</ref>
      <ref url="http://securitytracker.com/id?1023670" source="SECTRACK">1023670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(1a)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(1b)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2)su1" />
        <vers num="6.1(2)su1a" />
        <vers num="6.1(3)" />
        <vers num="6.1(4)" />
        <vers num="6.1.0" />
        <vers num="7.0" />
        <vers num="7.0(1)" />
        <vers num="7.0(2)" />
        <vers num="7.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0592" published="2010-03-05" name="CVE-2010-0592" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml" source="CISCO" patch="1" adv="1">20100303 Cisco Unified Communications Manager Denial of Service Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38497" source="BID">38497</ref>
      <ref url="http://securitytracker.com/id?1023670" source="SECTRACK">1023670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="4.1" edition="(3)sr.5" />
        <vers num="4.1" edition="(3)sr4" />
        <vers num="4.1" edition="(3)sr5" />
        <vers num="4.1" edition="(3)sr5b" />
        <vers num="4.1" edition="(3)sr5c" />
        <vers num="4.1(3)" />
        <vers num="4.1(3)sr1" />
        <vers num="4.1(3)sr2" />
        <vers num="4.1(3)sr3" />
        <vers num="4.1(3)sr4" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.2" edition="4.2(3)sr.2" />
        <vers num="4.2" edition="4.2_(3)sr2b" />
        <vers num="4.2" edition="4.2_(3)sr3" />
        <vers num="4.2(3)sr1" />
        <vers num="4.2(3)sr2b" />
        <vers num="4.2(3)sr3" />
        <vers num="4.2(3)sr4" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.3_sr3" />
        <vers num="4.2.3sr1" />
        <vers num="4.2.3sr2" />
        <vers num="4.2.3sr2b" />
        <vers num="4.2_1" />
        <vers num="4.2_2" />
        <vers num="4.2_3" />
        <vers num="4.2_3sr1" />
        <vers num="4.3" edition="4.3(1)sr.1" />
        <vers num="4.3(1)" />
        <vers num="4.3(1)sr.1" />
        <vers num="4.3(2)" />
        <vers num="4.3(2)sr1" />
        <vers num="4.3.1" />
        <vers num="4.3_1" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(1a)" />
        <vers num="6.1" edition="(1a)" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(1b)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2)su1" />
        <vers num="6.1(2)su1a" />
        <vers num="6.1.0" />
        <vers num="7.0" />
        <vers num="7.0(1)" />
        <vers num="7.0(2)" />
        <vers num="7.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0593" published="2010-04-22" name="CVE-2010-0593" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b27511.shtml" source="CISCO" patch="1" adv="1">20100421 Cisco Small Business Video Surveillance Cameras and Cisco 4-Port Gigabit Security Routers Authentication Bypass Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58034" source="XF">cisco-small-business-unauth-access(58034)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0965" source="VUPEN">ADV-2010-0965</ref>
      <ref url="http://www.securitytracker.com/id?1023906" source="SECTRACK">1023906</ref>
      <ref url="http://www.securityfocus.com/bid/39612" source="BID">39612</ref>
      <ref url="http://secunia.com/advisories/39510" source="SECUNIA">39510</ref>
      <ref url="http://osvdb.org/63978" source="OSVDB">63978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pvc2300">
        <vers prev="1" num="1.1.1.4" />
      </prod>
      <prod vendor="cisco" name="rvs4000">
        <vers num="1.3.0.5" />
        <vers prev="1" num="1.3.1.0" />
      </prod>
      <prod vendor="cisco" name="wvc200">
        <vers num="1.1.0.12" />
        <vers prev="1" num="1.1.0.15" />
      </prod>
      <prod vendor="cisco" name="wvc210">
        <vers num="1.1.0.12" />
        <vers prev="1" num="1.1.0.15" />
      </prod>
      <prod vendor="cisco" name="wvc2300">
        <vers prev="1" num="1.1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0594" published="2010-05-04" name="CVE-2010-0594" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Cisco Router and Security Device Manager (SDM) allows remote attackers to inject arbitrary web script or HTML via unknown vectors, aka Bug ID CSCtb38467.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000014.html" source="JVNDB">JVNDB-2010-000014</ref>
      <ref url="http://jvn.jp/en/jp/JVN14313132/index.html" source="JVN">JVN#14313132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="router_and_security_device_manager">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0595" published="2010-05-27" name="CVE-2010-0595" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 has a default password for the administrative user account and unspecified other accounts, which makes it easier for remote attackers to obtain privileged access, aka Bug ID CSCtb83495.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58893" source="XF">cisco-nbn-default-credentials(58893)</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/40380" source="BID">40380</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="1.5.1" />
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0596" published="2010-05-27" name="CVE-2010-0596" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Mediator Framework 2.2 before 2.2.1.dev.1 and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 allows remote authenticated users to read or modify the device configuration, and gain privileges, via a (1) HTTP or (2) HTTPS request, aka Bug ID CSCtb83607.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1" adv="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0597" published="2010-05-27" name="CVE-2010-0597" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 allows remote authenticated users to read or modify the device configuration, and gain privileges or cause a denial of service (device reload), via a (1) XML RPC or (2) XML RPC over HTTPS request, aka Bug ID CSCtb83618.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/40386" source="BID">40386</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="1.5.1" />
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0598" published="2010-05-27" name="CVE-2010-0598" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt HTTP sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83631.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="1.5.1" />
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0599" published="2010-05-27" name="CVE-2010-0599" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83505.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1" adv="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="1.5.1" />
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0600" published="2010-05-27" name="CVE-2010-0600" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not properly restrict network access to an unspecified configuration file, which allows remote attackers to read passwords and unspecified other account details via a (1) XML RPC or (2) XML RPC over HTTPS session, aka Bug ID CSCtb83512.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/757804" source="CERT-VN">VU#757804</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c518.shtml" source="CISCO" patch="1" adv="1">20100526 Multiple Vulnerabilities in Cisco Network Building Mediator</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-10-147-01_Cisco_Network_Building_Mediator.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/40384" source="BID">40384</ref>
      <ref url="http://securitytracker.com/id?1024027" source="SECTRACK">1024027</ref>
      <ref url="http://secunia.com/advisories/39904" source="SECUNIA">39904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="mediator_framework">
        <vers num="1.5.1" />
        <vers num="2.2" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0601" published="2010-05-14" name="CVE-2010-0601" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The MGCP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsl39126.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40117" source="BID">40117</ref>
      <ref url="http://osvdb.org/64680" source="OSVDB">64680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)s" />
        <vers num="9.7(3)s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0602" published="2010-05-14" name="CVE-2010-0602" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsk32606.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40120" source="BID">40120</ref>
      <ref url="http://osvdb.org/64688" source="OSVDB">64688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)s" />
        <vers num="9.7(3)s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0603" published="2010-05-14" name="CVE-2010-0603" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via a malformed session attribute, aka Bug ID CSCsk40030.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40121" source="BID">40121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)s" />
        <vers num="9.7(3)s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0604" published="2010-05-14" name="CVE-2010-0604" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via unknown SIP traffic, as demonstrated by "SIP testing," aka Bug ID CSCsk38165.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40122" source="BID">40122</ref>
      <ref url="http://osvdb.org/64686" source="OSVDB">64686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)s" />
        <vers num="9.7(3)s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0605" published="2010-02-11" name="CVE-2010-0605" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osticket.com/forums/project.php?issueid=176" source="CONFIRM" patch="1">http://osticket.com/forums/project.php?issueid=176</ref>
      <ref url="http://www.securityfocus.com/bid/38166" source="BID">38166</ref>
      <ref url="http://www.exploit-db.com/exploits/11380" source="EXPLOIT-DB">11380</ref>
      <ref url="http://secunia.com/advisories/38515" source="SECUNIA" adv="1">38515</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-SQLi.pdf" source="MISC">http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-SQLi.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="1" />
        <vers num="1.2.7" />
        <vers num="1.3.0" />
        <vers prev="1" num="1.6" edition="rc1" />
        <vers prev="1" num="1.6" edition="rc2" />
        <vers prev="1" num="1.6" edition="rc3" />
        <vers prev="1" num="1.6" edition="rc4" />
        <vers prev="1" num="1.6" edition="rc5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0606" published="2010-02-11" name="CVE-2010-0606" modified="2010-11-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://osticket.com/forums/project.php?issueid=176" source="CONFIRM" patch="1">http://osticket.com/forums/project.php?issueid=176</ref>
      <ref url="http://www.securityfocus.com/bid/38166" source="BID">38166</ref>
      <ref url="http://secunia.com/advisories/38515" source="SECUNIA" adv="1">38515</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-ReflectedXSS.pdf" source="MISC">http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-ReflectedXSS.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osticket" name="osticket">
        <vers num="1" />
        <vers num="1.2.7" />
        <vers num="1.3.0" />
        <vers prev="1" num="1.6" edition="rc1" />
        <vers prev="1" num="1.6" edition="rc2" />
        <vers prev="1" num="1.6" edition="rc3" />
        <vers prev="1" num="1.6" edition="rc4" />
        <vers prev="1" num="1.6" edition="rc5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0607" published="2010-02-11" name="CVE-2010-0607" modified="2010-11-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38463" source="SECUNIA" adv="1">38463</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/sterlite-xss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/sterlite-xss.txt</ref>
      <ref url="http://osvdb.org/62211" source="OSVDB">62211</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=126531284626756&amp;w=2" source="FULLDISC">20100204 Sterlite SAM300AX ADSL router - Cross Site</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sterlitetechnologies" name="sam300_ax_router">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0608" published="2010-02-11" name="CVE-2010-0608" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37988" source="BID">37988</ref>
      <ref url="http://www.osvdb.org/62002" source="OSVDB">62002</ref>
      <ref url="http://www.exploit-db.com/exploits/11278" source="EXPLOIT-DB">11278</ref>
      <ref url="http://secunia.com/advisories/38368" source="SECUNIA" adv="1">38368</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/novaboard112-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/novaboard112-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novaboard" name="novaboard">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0609" published="2010-02-11" name="CVE-2010-0609" modified="2010-11-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/62003" source="OSVDB">62003</ref>
      <ref url="http://secunia.com/advisories/38368" source="SECUNIA" adv="1">38368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novaboard" name="novaboard">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0610" published="2010-02-11" name="CVE-2010-0610" modified="2010-10-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php.  NOTE: a separate vector for the id parameter to detail.php may also exist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56135" source="XF">photoblog-blog-sql-injection(56135)</ref>
      <ref url="http://www.securityfocus.com/bid/38136" source="BID">38136</ref>
      <ref url="http://www.exploit-db.com/exploits/11337" source="EXPLOIT-DB">11337</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/joomlaphotoblog-bsql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/joomlaphotoblog-bsql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webguerilla" name="com_photoblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0611" published="2010-02-11" name="CVE-2010-0611" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56147" source="XF">baalsystems-adminlogin-sql-injection(56147)</ref>
      <ref url="http://www.securityfocus.com/bid/38139" source="BID">38139</ref>
      <ref url="http://www.exploit-db.com/exploits/11346" source="EXPLOIT-DB">11346</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/baalsystems-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/baalsystems-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="baalsystems" name="baal_systems">
        <vers num="3.6" />
        <vers num="3.7" />
        <vers prev="1" num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0612" published="2010-02-11" name="CVE-2010-0612" modified="2010-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in DocumentManager before 4.0 has unknown impact and attack vectors, related to file rights.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://freshmeat.net/projects/dmanager/releases/311735" source="CONFIRM" patch="1">http://freshmeat.net/projects/dmanager/releases/311735</ref>
      <ref url="http://www.osvdb.org/62032" source="OSVDB">62032</ref>
      <ref url="http://secunia.com/advisories/38441" source="SECUNIA" adv="1">38441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmanager" name="documentmanager">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="2.0" />
        <vers prev="1" num="3.0" edition="b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0613" published="2010-02-11" name="CVE-2010-0613" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in viewfile.php in ARWScripts Fonts Script allows remote attackers to read arbitrary local files via directory traversal sequences in a base64-encoded f parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38709" source="BID">38709</ref>
      <ref url="http://secunia.com/advisories/38518" source="SECUNIA" adv="1">38518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arwscripts" name="fonts_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0614" published="2010-02-11" name="CVE-2010-0614" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56152" source="XF">evalsmsi-ajax-sql-injection(56152)</ref>
      <ref url="http://www.securityfocus.com/bid/38116" source="BID">38116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509370/100/0/threaded" source="BUGTRAQ">20100204 CORELAN-10-008 - Multiple vulnerabilities found in evalmsi 2.1.03</ref>
      <ref url="http://www.osvdb.org/62177" source="OSVDB">62177</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/</ref>
      <ref url="http://secunia.com/advisories/38478" source="SECUNIA" adv="1">38478</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myshell" name="evalsmsi">
        <vers num="2.1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0615" published="2010-02-11" name="CVE-2010-0615" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56154" source="XF">evalsmsi-comment-xss(56154)</ref>
      <ref url="http://www.securityfocus.com/bid/38116" source="BID">38116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509370/100/0/threaded" source="BUGTRAQ">20100204 CORELAN-10-008 - Multiple vulnerabilities found in evalmsi 2.1.03</ref>
      <ref url="http://www.osvdb.org/62178" source="OSVDB">62178</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/</ref>
      <ref url="http://secunia.com/advisories/38478" source="SECUNIA" adv="1">38478</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myshell" name="evalsmsi">
        <vers num="2.1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0616" published="2010-02-11" name="CVE-2010-0616" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges.  NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38116" source="BID">38116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509370/100/0/threaded" source="BUGTRAQ">20100204 CORELAN-10-008 - Multiple vulnerabilities found in evalmsi 2.1.03</ref>
      <ref url="http://www.osvdb.org/62180" source="OSVDB">62180</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-008-evalmsi-2-1-03-multiple-vulnerabilities/</ref>
      <ref url="http://secunia.com/advisories/38478" source="SECUNIA" adv="1">38478</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/corelan-10-008-evalmsi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myshell" name="evalsmsi">
        <vers num="2.1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0617" published="2010-02-11" name="CVE-2010-0617" modified="2010-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56157" source="XF">evalsmsi-ajax-xss(56157)</ref>
      <ref url="http://www.osvdb.org/62179" source="OSVDB">62179</ref>
      <ref url="http://secunia.com/advisories/38478" source="SECUNIA" adv="1">38478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myshell" name="evalsmsi">
        <vers num="2.1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0618" published="2010-03-24" name="CVE-2010-0618" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows remote attackers to cause a denial of service (TCP outage) by making many passive FTP connections and then aborting these connections.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://support.lexmark.com/index?page=content&amp;id=TE85&amp;locale=EN&amp;userlocale=EN_US#Printcryption

'Details

Lexmark products have connection flood protection mechanisms that limit the number of simultaneous network connections that can be made to the device on most TCP service ports.

(21/FTP 79/Finger, 515/LPD, 631/IPP, 5001, 9100-9104, 9200, 9300, 9400, 9500-9501 &amp; 9600)

The FTP service exception handler does not properly maintain the state of the flood protection when passive FTP connections are aborted. Once a sufficient number of passive FTP connections have timed out (typically 15), the flood protection is enabled and is never reset.

The flood protection can be reset by resetting the network adapter, or by power cycling the device.

The firmware update that resolves this vulnerability automatically resets the flood protection after the “Network Job Timeout” has expired or 90 seconds if the “Network Job Timeout” is disabled.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38906" source="BID">38906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510285/100/0/threaded" source="BUGTRAQ">20100322 {PRL} Lexmark Multiple Laser printer FTP Remote Denial of Services</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=11&amp;Itemid=11" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=11&amp;Itemid=11</ref>
      <ref url="http://support.lexmark.com/index?page=content&amp;id=TE85&amp;locale=EN&amp;userlocale=EN_US" source="CONFIRM" adv="1">http://support.lexmark.com/index?page=content&amp;id=TE85&amp;locale=EN&amp;userlocale=EN_US</ref>
      <ref url="http://secunia.com/advisories/39056" source="SECUNIA">39056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="z2420">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0619" published="2010-03-24" name="CVE-2010-0619" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:P/A:C)" CVSS_score="7.3" CVSS_impact_subscore="9.5" CVSS_exploit_subscore="4.9" CVSS_base_score="7.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser printers and multi-function printers allows remote attackers to execute arbitrary code or cause a denial of service (device hang) via a long argument to a PJL INQUIRE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38901" source="BID">38901</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510251/100/0/threaded" source="BUGTRAQ">20100322 {PRL} Lexmark Multiple Laser Printer Remote Stack Overflow</ref>
      <ref url="http://support.lexmark.com/index?page=content&amp;id=TE84&amp;locale=EN&amp;userlocale=EN_US" source="CONFIRM" adv="1">http://support.lexmark.com/index?page=content&amp;id=TE84&amp;locale=EN&amp;userlocale=EN_US</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lexmark" name="x94x">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0620" published="2010-02-24" name="CVE-2010-0620" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.</descript>
      <descript source="nvd">Per: http://seclists.org/bugtraq/2010/Feb/222

Affected products:

EMC HomeBase Server version 6.2.x

EMC HomeBase Server version 6.3.x
</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-020/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-020/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0458" source="VUPEN" adv="1">ADV-2010-0458</ref>
      <ref url="http://www.securityfocus.com/bid/38380" source="BID">38380</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509723/100/0/threaded" source="BUGTRAQ">20100224 ESA-2010-003: EMC HomeBase Server Arbitrary File Upload Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/8230" source="SREASON">8230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="homebase_server">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0622" published="2010-02-15" name="CVE-2010-0622" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=563091" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=563091</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0161.html" source="REDHAT">RHSA-2010:0161</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/11/2" source="MLIST">[oss-security] 20100211 Re: CVE request - kernel: futex: Handle user space corruption gracefully</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/09/2" source="MLIST">[oss-security] 20100209 CVE request - kernel: futex: Handle user space corruption gracefully</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:088" source="MANDRIVA">MDVSA-2010:088</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2005" source="DEBIAN">DSA-2005</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39033" source="SECUNIA">39033</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://secunia.com/advisories/38905" source="SECUNIA">38905</ref>
      <ref url="http://secunia.com/advisories/38779" source="SECUNIA">38779</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9655" source="OVAL">oval:org.mitre.oval:def:9655</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE">SUSE-SA:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00000.html" source="SUSE">SUSE-SA:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035070.html" source="FEDORA">FEDORA-2010-1804</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=51246bfd189064079c54421507236fd2723b18f3" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=51246bfd189064079c54421507236fd2723b18f3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers prev="1" num="2.6.33" edition="rc4" />
        <vers prev="1" num="2.6.33" edition="rc5" />
        <vers prev="1" num="2.6.33" edition="rc6" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0623" published="2010-02-15" name="CVE-2010-0623" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0638" source="VUPEN">ADV-2010-0638</ref>
      <ref url="http://www.ubuntu.com/usn/USN-914-1" source="UBUNTU">USN-914-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/11/2" source="MLIST">[oss-security] 20100211 Re: CVE request - kernel: futex: Handle user space corruption gracefully</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:088" source="MANDRIVA">MDVSA-2010:088</ref>
      <ref url="http://secunia.com/advisories/38922" source="SECUNIA">38922</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00006.html" source="SUSE">SUSE-SA:2010:018</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5ecb01cfdf96c5f465192bdb2a4fd4a61a24c6cc" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=5ecb01cfdf96c5f465192bdb2a4fd4a61a24c6cc</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=14256" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=14256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers prev="1" num="2.6.33" edition="rc4" />
        <vers prev="1" num="2.6.33" edition="rc5" />
        <vers prev="1" num="2.6.33" edition="rc6" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0624" published="2010-03-15" name="CVE-2010-0624" modified="2012-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=564368" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=564368</ref>
      <ref url="https://issues.rpath.com/browse/RPL-3219" source="CONFIRM">https://issues.rpath.com/browse/RPL-3219</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0729" source="VUPEN">ADV-2010-0729</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0728" source="VUPEN">ADV-2010-0728</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0687" source="VUPEN">ADV-2010-0687</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0639" source="VUPEN">ADV-2010-0639</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0629" source="VUPEN">ADV-2010-0629</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0628" source="VUPEN">ADV-2010-0628</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514503/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0070-1 cpio tar</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0145.html" source="REDHAT">RHSA-2010:0145</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0144.html" source="REDHAT">RHSA-2010:0144</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0142.html" source="REDHAT">RHSA-2010:0142</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0141.html" source="REDHAT">RHSA-2010:0141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:065" source="MANDRIVA">MDVSA-2010:065</ref>
      <ref url="http://www.agrs.tu-berlin.de/index.php?id=78327" source="MISC">http://www.agrs.tu-berlin.de/index.php?id=78327</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201111-11.xml" source="GENTOO">GLSA-201111-11</ref>
      <ref url="http://secunia.com/advisories/39008" source="SECUNIA">39008</ref>
      <ref url="http://secunia.com/advisories/38988" source="SECUNIA">38988</ref>
      <ref url="http://secunia.com/advisories/38869" source="SECUNIA">38869</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6907" source="OVAL">oval:org.mitre.oval:def:6907</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10277" source="OVAL">oval:org.mitre.oval:def:10277</ref>
      <ref url="http://osvdb.org/62950" source="OSVDB">62950</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038149.html" source="FEDORA">FEDORA-2010-4306</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038134.html" source="FEDORA">FEDORA-2010-4302</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037401.html" source="FEDORA">FEDORA-2010-4321</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037395.html" source="FEDORA">FEDORA-2010-4309</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036668.html" source="FEDORA">FEDORA-2010-2895</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="cpio">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers prev="1" num="2.10" />
        <vers num="2.4-2" />
        <vers num="2.5" />
        <vers num="2.5.90" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
      <prod vendor="gnu" name="tar">
        <vers num="1.13" />
        <vers num="1.13.11" />
        <vers num="1.13.14" />
        <vers num="1.13.16" />
        <vers num="1.13.17" />
        <vers num="1.13.18" />
        <vers num="1.13.19" />
        <vers num="1.13.25" />
        <vers num="1.13.5" />
        <vers num="1.14" />
        <vers num="1.14.1" />
        <vers num="1.14.90" />
        <vers num="1.15" />
        <vers num="1.15.1" />
        <vers num="1.15.90" />
        <vers num="1.15.91" />
        <vers num="1.16" />
        <vers num="1.16.1" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.19" />
        <vers num="1.20" />
        <vers num="1.21" />
        <vers prev="1" num="1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0625" published="2010-04-05" name="CVE-2010-0625" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=569496" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=569496</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-062" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-062</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0742" source="VUPEN" adv="1">ADV-2010-0742</ref>
      <ref url="http://www.securityfocus.com/bid/39041" source="BID">39041</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510557/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-062: Novell Netware NWFTPD RMD/RNFR/DELE Argument Parsing Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510353/100/0/threaded" source="BUGTRAQ">20100329 {PRL} Novell Netware FTP Remote Stack Overflow</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=12&amp;Itemid=12" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=12&amp;Itemid=12</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3238588&amp;sliceId=1</ref>
      <ref url="http://securitytracker.com/id?1023768" source="SECTRACK">1023768</ref>
      <ref url="http://secunia.com/advisories/39151" source="SECUNIA" adv="1">39151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netware_ftp_server">
        <vers num="5.01i" />
        <vers num="5.01o" />
        <vers num="5.01w" />
        <vers num="5.01y" />
        <vers num="5.02b" />
        <vers num="5.02i" />
        <vers num="5.02r" />
        <vers num="5.02y" />
        <vers num="5.03b" />
        <vers num="5.03l" />
        <vers num="5.04.20" />
        <vers num="5.04.25" />
        <vers num="5.04.5" />
        <vers num="5.04.8" />
        <vers num="5.05" />
        <vers num="5.05.04" />
        <vers num="5.06.04" />
        <vers num="5.06.05" />
        <vers num="5.07" />
        <vers num="5.07.02" />
      </prod>
      <prod vendor="novell" name="netware">
        <vers num="5.1" edition="sp2a" />
        <vers num="5.1" edition="sp3" />
        <vers num="5.1" edition="sp4" />
        <vers num="5.1" edition="sp6" />
        <vers num="6.0" edition="sp1" />
        <vers num="6.0" edition="sp2" />
        <vers num="6.0" edition="sp3" />
        <vers num="6.5" edition="sp1" />
        <vers num="6.5" edition="sp1.1a" />
        <vers num="6.5" edition="sp1.1b" />
        <vers num="6.5" edition="sp2" />
        <vers num="6.5" edition="sp3" />
        <vers num="6.5" edition="sp4" />
        <vers num="6.5" edition="sp5" />
        <vers num="6.5" edition="sp6" />
        <vers num="6.5" edition="sp7" />
        <vers num="6.5" edition="sp8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0628" published="2010-03-25" name="CVE-2010-0628" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in the SPNEGO GSS-API functionality in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2 and 1.8 before 1.8.1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid packet that triggers incorrect preparation of an error token.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38904" source="BID" patch="1">38904</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=566258" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=566258</ref>
      <ref url="http://www.ubuntu.com/usn/USN-916-1" source="UBUNTU">USN-916-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510281/100/0/threaded" source="BUGTRAQ">20100323 MITKRB5-SA-2010-002 denial of service in SPNEGO [CVE-2010-0628 VU#839413]</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-002.txt" source="CONFIRM">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-002.txt</ref>
      <ref url="http://secunia.com/advisories/39023" source="SECUNIA">39023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0629" published="2010-04-07" name="CVE-2010-0629" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt

'AFFECTED SOFTWARE
=================

* kadmind in MIT releases krb5-1.5 through krb5-1.6.3.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39247" source="BID" patch="1">39247</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-003.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0876" source="VUPEN">ADV-2010-0876</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510566/100/0/threaded" source="BUGTRAQ">20100406 MITKRB5-SA-2010-003 [CVE-2010-0629] denial of service in kadmind in older krb5 releases</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0343.html" source="REDHAT">RHSA-2010:0343</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:071" source="MANDRIVA">MDVSA-2010:071</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2031" source="DEBIAN">DSA-2031</ref>
      <ref url="http://ubuntu.com/usn/usn-924-1" source="UBUNTU">USN-924-1</ref>
      <ref url="http://securitytracker.com/id?1023821" source="SECTRACK">1023821</ref>
      <ref url="http://secunia.com/advisories/39367" source="SECUNIA">39367</ref>
      <ref url="http://secunia.com/advisories/39324" source="SECUNIA">39324</ref>
      <ref url="http://secunia.com/advisories/39315" source="SECUNIA">39315</ref>
      <ref url="http://secunia.com/advisories/39290" source="SECUNIA">39290</ref>
      <ref url="http://secunia.com/advisories/39264" source="SECUNIA">39264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9489" source="OVAL">oval:org.mitre.oval:def:9489</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html" source="SUSE">SUSE-SR:2010:009</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038556.html" source="FEDORA">FEDORA-2010-6108</ref>
      <ref url="http://krbdev.mit.edu/rt/Ticket/Display.html?id=5998" source="CONFIRM">http://krbdev.mit.edu/rt/Ticket/Display.html?id=5998</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567052" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0630" published="2010-02-12" name="CVE-2010-0630" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56043" source="XF">freejokescript-viewjokes-sql-injection(56043)</ref>
      <ref url="http://www.securityfocus.com/bid/38020" source="BID">38020</ref>
      <ref url="http://www.exploit-db.com/exploits/11306" source="EXPLOIT-DB">11306</ref>
      <ref url="http://secunia.com/advisories/35434" source="SECUNIA" adv="1">35434</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/evernewfjs-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/evernewfjs-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evernewscripts" name="free_joke_script">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0631" published="2010-02-12" name="CVE-2010-0631" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11323" source="EXPLOIT-DB">11323</ref>
      <ref url="http://secunia.com/advisories/38389" source="SECUNIA" adv="1">38389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eicrasoft" name="eicra_car_rental-script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0632" published="2010-02-12" name="CVE-2010-0632" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56028" source="XF">simplefaq-catid-sql-injection(56028)</ref>
      <ref url="http://www.securityfocus.com/bid/38015" source="BID">38015</ref>
      <ref url="http://www.exploit-db.com/exploits/11294" source="EXPLOIT-DB">11294</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlasimplefaq-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlasimplefaq-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parkviewconsultants" name="com_simplefaq">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0633" published="2010-02-12" name="CVE-2010-0633" modified="2010-03-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.citrix.com/article/CTX123460" source="CONFIRM" patch="1">http://support.citrix.com/article/CTX123460</ref>
      <ref url="http://support.citrix.com/article/CTX123456" source="CONFIRM" patch="1" adv="1">http://support.citrix.com/article/CTX123456</ref>
      <ref url="http://support.citrix.com/article/CTX123193" source="CONFIRM" patch="1">http://support.citrix.com/article/CTX123193</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0290" source="VUPEN" adv="1">ADV-2010-0290</ref>
      <ref url="http://www.securitytracker.com/id?1023530" source="SECTRACK">1023530</ref>
      <ref url="http://www.securityfocus.com/bid/38052" source="BID">38052</ref>
      <ref url="http://secunia.com/advisories/38431" source="SECUNIA" adv="1">38431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citrix" name="xenserver">
        <vers prev="1" num="5.0" edition="update_3" />
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0634" published="2010-02-12" name="CVE-2010-0634" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Fast Lexical Analyzer Generator (flex) before 2.5.35 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://freshmeat.net/projects/flex/releases/311661" source="CONFIRM" patch="1">http://freshmeat.net/projects/flex/releases/311661</ref>
      <ref url="http://osvdb.org/62029" source="OSVDB">62029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="will_estes" name="flex">
        <vers num="2.5.27" />
        <vers num="2.5.31" />
        <vers num="2.5.33" />
        <vers prev="1" num="2.5.34" />
        <vers num="2.5.4a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0635" published="2010-02-12" name="CVE-2010-0635" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.jevents.net/forum/viewtopic.php?f=17&amp;t=3910#p15526" source="CONFIRM" patch="1">http://www.jevents.net/forum/viewtopic.php?f=17&amp;t=3910#p15526</ref>
      <ref url="http://www.securityfocus.com/bid/38050" source="BID">38050</ref>
      <ref url="http://secunia.com/advisories/38404" source="SECUNIA" adv="1">38404</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jevents" name="jevents_search_plugin">
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0636" published="2010-02-12" name="CVE-2010-0636" modified="2010-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38053" source="BID">38053</ref>
      <ref url="http://secunia.com/advisories/38222" source="SECUNIA" adv="1">38222</ref>
      <ref url="http://holisticinfosec.org/content/view/133/45/" source="MISC">http://holisticinfosec.org/content/view/133/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k5n" name="webcalendar">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0637" published="2010-02-12" name="CVE-2010-0637" modified="2010-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38222" source="SECUNIA" adv="1">38222</ref>
      <ref url="http://holisticinfosec.org/content/view/133/45/" source="MISC">http://holisticinfosec.org/content/view/133/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k5n" name="webcalendar">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0638" published="2010-02-15" name="CVE-2010-0638" modified="2010-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38222" source="SECUNIA" adv="1">38222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k5n" name="webcalendar">
        <vers num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0639" published="2010-02-15" name="CVE-2010-0639" modified="2010-08-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.squid-cache.org/Versions/v3/3.0/changesets/3.0-ADV-2010_2.patch" source="MISC" patch="1">http://www.squid-cache.org/Versions/v3/3.0/changesets/3.0-ADV-2010_2.patch</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.7/changesets/12600.patch" source="MISC" patch="1">http://www.squid-cache.org/Versions/v2/2.7/changesets/12600.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0603" source="VUPEN" adv="1">ADV-2010-0603</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0371" source="VUPEN" adv="1">ADV-2010-0371</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2010_2.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2010_2.txt</ref>
      <ref url="http://www.securitytracker.com/id?1023587" source="SECTRACK">1023587</ref>
      <ref url="http://www.securityfocus.com/bid/38212" source="BID">38212</ref>
      <ref url="http://secunia.com/advisories/38812" source="SECUNIA" adv="1">38812</ref>
      <ref url="http://osvdb.org/62297" source="OSVDB">62297</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037159.html" source="FEDORA">FEDORA-2010-2434</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035961.html" source="FEDORA">FEDORA-2010-3064</ref>
      <ref url="http://bugs.squid-cache.org/show_bug.cgi?id=2858" source="MISC">http://bugs.squid-cache.org/show_bug.cgi?id=2858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid-cache" name="squid">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" edition="stable3" />
        <vers num="2.7" edition="stable4" />
        <vers num="3.0" />
        <vers num="3.0.stable1" />
        <vers num="3.0.stable11" />
        <vers num="3.0.stable12" />
        <vers num="3.0.stable13" />
        <vers num="3.0.stable14" />
        <vers num="3.0.stable15" />
        <vers num="3.0.stable16" />
        <vers num="3.0.stable17" />
        <vers num="3.0.stable18" />
        <vers num="3.0.stable19" />
        <vers num="3.0.stable2" />
        <vers num="3.0.stable20" />
        <vers num="3.0.stable21" />
        <vers num="3.0.stable22" />
        <vers num="3.0.stable23" />
        <vers num="3.0.stable3" />
        <vers num="3.0.stable4" />
        <vers num="3.0.stable5" />
        <vers num="3.0.stable6" />
        <vers num="3.0.stable7" />
        <vers num="3.0.stable8" />
        <vers num="3.0.stable9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0640" published="2010-02-24" name="CVE-2010-0640" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38376" source="BID">38376</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509714/100/0/threaded" source="BUGTRAQ">20100223 CA20100223-01: Security Notice for CA eHealth Performance Manager</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Feb/415" source="FULLDISC">20100223 CA20100223-01: Security Notice for CA eHealth Performance Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="ehealth_performance_manager">
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0641" published="2010-02-17" name="CVE-2010-0641" modified="2010-02-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56220" source="XF">ccs-loginpage-xss(56220)</ref>
      <ref url="http://www.securityfocus.com/bid/38201" source="BID">38201</ref>
      <ref url="http://www.exploit-db.com/exploits/11403" source="EXPLOIT-DB">11403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="collaboration_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0642" published="2010-02-17" name="CVE-2010-0642" modified="2010-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending %00 after .jhtml, and (4) appending %c0%80 after .jhtml, related to the (a) doc/docindex.jhtml, (b) browserId/wizardForm.jhtml, (c) webline/html/forms/callback.jhtml, (d) webline/html/forms/callbackICM.jhtml, (e) webline/html/agent/AgentFrame.jhtml, (f) webline/html/agent/default/badlogin.jhtml, (g) callme/callForm.jhtml, (h) webline/html/multichatui/nowDefunctWindow.jhtml, (i) browserId/wizard.jhtml, (j) admin/CiscoAdmin.jhtml, (k) msccallme/mscCallForm.jhtml, and (l) webline/html/admin/wcs/LoginPage.jhtml components.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56221" source="XF">ccs-files-information-disclosure(56221)</ref>
      <ref url="http://www.securityfocus.com/bid/38202" source="BID">38202</ref>
      <ref url="http://www.exploit-db.com/exploits/11403" source="EXPLOIT-DB">11403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="collaboration_server">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0643" published="2010-02-18" name="CVE-2010-0643" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56212" source="XF">googlechrome-fallback-info-disc(56212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.osvdb.org/62315" source="OSVDB">62315</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14500" source="OVAL">oval:org.mitre.oval:def:14500</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=12303" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=12303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0644" published="2010-02-18" name="CVE-2010-0644" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome before 4.0.249.89, when a SOCKS 5 proxy server is configured, sends DNS queries directly, which allows remote DNS servers to obtain potentially sensitive information about the identity of a client user via request logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" patch="1" adv="1">ADV-2010-0361</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13926" source="OVAL">oval:org.mitre.oval:def:13926</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=29914" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=29914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0645" published="2010-02-18" name="CVE-2010-0645" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56213" source="XF">googlechrome-v8engine-code-exec(56213)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.osvdb.org/62316" source="OSVDB">62316</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14508" source="OVAL">oval:org.mitre.oval:def:14508</ref>
      <ref url="http://codereview.chromium.org/525064" source="CONFIRM">http://codereview.chromium.org/525064</ref>
      <ref url="http://code.google.com/p/v8/source/detail?r=3560" source="CONFIRM">http://code.google.com/p/v8/source/detail?r=3560</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31009" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0646" published="2010-02-18" name="CVE-2010-0646" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" patch="1" adv="1">ADV-2010-0361</ref>
      <ref url="http://codereview.chromium.org/525064" source="CONFIRM" patch="1">http://codereview.chromium.org/525064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56213" source="XF">googlechrome-v8engine-code-exec(56213)</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.osvdb.org/62316" source="OSVDB">62316</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14222" source="OVAL">oval:org.mitre.oval:def:14222</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/v8/source/detail?r=3560" source="CONFIRM">http://code.google.com/p/v8/source/detail?r=3560</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31009" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.78" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0647" published="2010-02-18" name="CVE-2010-0647" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a &lt;ruby>>&lt;table>&lt;rt> sequence.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=33266" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=33266</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56214" source="XF">googlechrome-ruby-tags-code-exec(56214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.osvdb.org/62317" source="OSVDB">62317</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/53525" source="CONFIRM">http://trac.webkit.org/changeset/53525</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14094" source="OVAL">oval:org.mitre.oval:def:14094</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31692" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers prev="1" num="r53475" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0648" published="2010-02-18" name="CVE-2010-0648" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12665" source="OVAL">oval:org.mitre.oval:def:12665</ref>
      <ref url="http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html" source="MISC">http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=32309" source="MISC">http://code.google.com/p/chromium/issues/detail?id=32309</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers prev="1" num="3.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0649" published="2010-02-18" name="CVE-2010-0649" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56217" source="XF">googlechrome-sandbox-code-exec(56217)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0361" source="VUPEN" adv="1">ADV-2010-0361</ref>
      <ref url="http://www.securityfocus.com/bid/38177" source="BID">38177</ref>
      <ref url="http://www.osvdb.org/62320" source="OSVDB">62320</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023583" source="SECTRACK">1023583</ref>
      <ref url="http://secunia.com/advisories/38545" source="SECUNIA" adv="1">38545</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14256" source="OVAL">oval:org.mitre.oval:def:14256</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=32915" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=32915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0650" published="2010-02-18" name="CVE-2010-0650" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=21501" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=21501</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/38373" source="BID">38373</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13791" source="OVAL">oval:org.mitre.oval:def:13791</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=3275" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=3275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.0" />
        <vers prev="1" num="4.0.249.78" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0651" published="2010-02-18" name="CVE-2010-0651" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=29820" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=29820</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://websec.sv.cmu.edu/css/css.pdf" source="MISC">http://websec.sv.cmu.edu/css/css.pdf</ref>
      <ref url="http://trac.webkit.org/changeset/52784" source="CONFIRM">http://trac.webkit.org/changeset/52784</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13653" source="OVAL">oval:org.mitre.oval:def:13653</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9877" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=9877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers prev="1" num="4.0.4" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers prev="1" num="r53524" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0652" published="2010-02-18" name="CVE-2010-0652" modified="2010-02-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9877" source="MISC">http://code.google.com/p/chromium/issues/detail?id=9877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0653" published="2010-02-18" name="CVE-2010-0653" modified="2010-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://websec.sv.cmu.edu/css/css.pdf" source="MISC">http://websec.sv.cmu.edu/css/css.pdf</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9877" source="MISC">http://code.google.com/p/chromium/issues/detail?id=9877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0654" published="2010-02-18" name="CVE-2010-0654" modified="2010-12-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=524223" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=524223</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-46.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-46.html</ref>
      <ref url="http://websec.sv.cmu.edu/css/css.pdf" source="MISC">http://websec.sv.cmu.edu/css/css.pdf</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11811" source="OVAL">oval:org.mitre.oval:def:11811</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9877" source="MISC">http://code.google.com/p/chromium/issues/detail?id=9877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0655" published="2010-02-18" name="CVE-2010-0655" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/416.html

'Use After Free CWE-416'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1" adv="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/secunia_research/2009-65/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-65/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14069" source="OVAL">oval:org.mitre.oval:def:14069</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=12523" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=12523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.78" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0656" published="2010-02-18" name="CVE-2010-0656" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=31329" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=31329</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/38372" source="BID">38372</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/51295" source="CONFIRM">http://trac.webkit.org/changeset/51295</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14501" source="OVAL">oval:org.mitre.oval:def:14501</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041436.html" source="FEDORA">FEDORA-2010-8423</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041432.html" source="FEDORA">FEDORA-2010-8379</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041383.html" source="FEDORA">FEDORA-2010-8360</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=20450" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=20450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers prev="1" num="r51280" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.78" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0657" published="2010-02-18" name="CVE-2010-0657" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/slices/2000.html

'Improper Encoding or Escaping of Output CWE-116'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14306" source="OVAL">oval:org.mitre.oval:def:14306</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=23693" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=23693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0658" published="2010-02-18" name="CVE-2010-0658" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13852" source="OVAL">oval:org.mitre.oval:def:13852</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=8864" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=8864</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=24646" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=24646</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=24071" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=24071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0659" published="2010-02-18" name="CVE-2010-0659" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=33231" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=33231</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://trac.webkit.org/changeset/52833" source="CONFIRM">http://trac.webkit.org/changeset/52833</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14079" source="OVAL">oval:org.mitre.oval:def:14079</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=28566" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=28566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers prev="1" num="r53524" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.78" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0660" published="2010-02-18" name="CVE-2010-0660" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14247" source="OVAL">oval:org.mitre.oval:def:14247</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=29920" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=29920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0661" published="2010-02-18" name="CVE-2010-0661" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.webkit.org/changeset/52401" source="CONFIRM" patch="1">http://trac.webkit.org/changeset/52401</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=32647" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=32647</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14482" source="OVAL">oval:org.mitre.oval:def:14482</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://flock.com/security/" source="CONFIRM">http://flock.com/security/</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=30660" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=30660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="52400" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0662" published="2010-02-18" name="CVE-2010-0662" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ParamTraits&lt;SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not use the correct variables in calculations designed to prevent integer overflows, which allows attackers to leverage renderer access to cause a denial of service or possibly have unspecified other impact via bitmap data, related to deserialization.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56627" source="XF">googlechrome-paramtraits-dos(56627)</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14457" source="OVAL">oval:org.mitre.oval:def:14457</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31307" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0663" published="2010-02-18" name="CVE-2010-0663" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ParamTraits&lt;SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sensitive information from process memory by providing insufficient data, related to use of a (1) thumbnail database or (2) HTML canvas.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14002" source="OVAL">oval:org.mitre.oval:def:14002</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31307" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31307</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0664" published="2010-02-18" name="CVE-2010-0664" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html" source="CONFIRM" patch="1">http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html</ref>
      <ref url="http://twitter.com/akirsanov/statuses/7370288490" source="MISC">http://twitter.com/akirsanov/statuses/7370288490</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs" source="CONFIRM" adv="1">http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs</ref>
      <ref url="http://securitytracker.com/id?1023506" source="SECTRACK">1023506</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14097" source="OVAL">oval:org.mitre.oval:def:14097</ref>
      <ref url="http://exchange.kg/other/chrome3_0day-denial_of_service_crash.html" source="MISC">http://exchange.kg/other/chrome3_0day-denial_of_service_crash.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31517" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers prev="1" num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0665" published="2010-02-19" name="CVE-2010-0665" modified="2010-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56228" source="XF">jag-database-info-disclosure(56228)</ref>
      <ref url="http://www.exploit-db.com/exploits/11406" source="EXPLOIT-DB">11406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xs4all" name="jag">
        <vers num="1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0666" published="2010-02-19" name="CVE-2010-0666" modified="2010-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=InfoDocument-patchbuilder-readme5067743&amp;sliceId=&amp;docTypeID=DT_SUSESDB_PSDB_1_1&amp;dialogID=122457794&amp;stateId=0%200%20122459671" source="CONFIRM" patch="1">http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=InfoDocument-patchbuilder-readme5067743&amp;sliceId=&amp;docTypeID=DT_SUSESDB_PSDB_1_1&amp;dialogID=122457794&amp;stateId=0%200%20122459671</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0334" source="VUPEN" adv="1">ADV-2010-0334</ref>
      <ref url="http://www.securitytracker.com/id?1023558" source="SECTRACK">1023558</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3426981" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3426981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="edirectory">
        <vers num="8.5" />
        <vers num="8.5.12a" />
        <vers num="8.5.27" />
        <vers num="8.6.2" />
        <vers num="8.7" />
        <vers num="8.7.1" edition="sp1" />
        <vers num="8.7.3" />
        <vers prev="1" num="8.7.3.10" />
        <vers num="8.7.3.8" />
        <vers num="8.7.3.8_presp9" />
        <vers num="8.7.3.9" />
        <vers num="8.8" edition="sp1" />
        <vers num="8.8" edition="sp2" />
        <vers num="8.8" edition="sp3" />
        <vers num="8.8" edition="sp4" />
        <vers num="8.8" edition="sp5" />
        <vers num="8.8" edition="sp5:patch1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0667" published="2010-02-26" name="CVE-2010-0667" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/15/2" source="MLIST">[oss-security] 20100215 CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/01/21/6" source="MLIST">[oss-security] 20100121 CVE request: MoinMoin information disclosure</ref>
      <ref url="http://secunia.com/advisories/38242" source="SECUNIA" adv="1">38242</ref>
      <ref url="http://moinmo.in/SecurityFixes" source="CONFIRM" adv="1">http://moinmo.in/SecurityFixes</ref>
      <ref url="http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18" source="CONFIRM">http://moinmo.in/MoinMoinChat/Logs/moin-dev/2010-01-18</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126676896601156&amp;w=2" source="MLIST">[oss-security] 20100221 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126625972814888&amp;w=2" source="MLIST">[oss-security] 20100215 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2" source="CONFIRM">http://hg.moinmo.in/moin/1.9/rev/9d8e7ce3c3a2</ref>
      <ref url="http://hg.moinmo.in/moin/1.9/rev/04afdde50094" source="CONFIRM">http://hg.moinmo.in/moin/1.9/rev/04afdde50094</ref>
      <ref url="http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES" source="CONFIRM">http://hg.moinmo.in/moin/1.9/raw-file/1.9.1/docs/CHANGES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0668" published="2010-02-26" name="CVE-2010-0668" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38023" source="BID" patch="1">38023</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=565604" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=565604</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56002" source="XF">moinmoin-superuser-unspecified(56002)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0600" source="VUPEN">ADV-2010-0600</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0266" source="VUPEN" adv="1">ADV-2010-0266</ref>
      <ref url="http://www.osvdb.org/62043" source="OSVDB">62043</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/15/2" source="MLIST">[oss-security] 20100215 CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2014" source="DEBIAN">DSA-2014</ref>
      <ref url="http://secunia.com/advisories/38903" source="SECUNIA">38903</ref>
      <ref url="http://secunia.com/advisories/38709" source="SECUNIA" adv="1">38709</ref>
      <ref url="http://secunia.com/advisories/38444" source="SECUNIA" adv="1">38444</ref>
      <ref url="http://moinmo.in/SecurityFixes" source="CONFIRM" adv="1">http://moinmo.in/SecurityFixes</ref>
      <ref url="http://moinmo.in/MoinMoinRelease1.8" source="CONFIRM">http://moinmo.in/MoinMoinRelease1.8</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126676896601156&amp;w=2" source="MLIST">[oss-security] 20100221 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126625972814888&amp;w=2" source="MLIST">[oss-security] 20100215 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035438.html" source="FEDORA">FEDORA-2010-1712</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035374.html" source="FEDORA">FEDORA-2010-1743</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES" source="CONFIRM">http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.5.0" edition="beta1" />
        <vers num="1.5.0" edition="beta2" />
        <vers num="1.5.0" edition="beta3" />
        <vers num="1.5.0" edition="beta4" />
        <vers num="1.5.0" edition="beta5" />
        <vers num="1.5.0" edition="beta6" />
        <vers num="1.5.0" edition="rc1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" edition="rc1" />
        <vers num="1.5.3" edition="rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" edition="rc1" />
        <vers num="1.5.5a" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.6.0" edition="beta1" />
        <vers num="1.6.0" edition="beta2" />
        <vers num="1.6.0" edition="rc1" />
        <vers num="1.6.0" edition="rc2" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.7.0" edition="beta1" />
        <vers num="1.7.0" edition="beta2" />
        <vers num="1.7.0" edition="rc1" />
        <vers num="1.7.0" edition="rc2" />
        <vers num="1.7.0" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.6" />
        <vers num="1.9.0" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0669" published="2010-02-26" name="CVE-2010-0669" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0600" source="VUPEN">ADV-2010-0600</ref>
      <ref url="http://www.securityfocus.com/bid/38023" source="BID">38023</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/21/2" source="MLIST">[oss-security] 20100221 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/15/4" source="MLIST">[oss-security] 20100215 Re: CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/15/2" source="MLIST">[oss-security] 20100215 CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2014" source="DEBIAN">DSA-2014</ref>
      <ref url="http://secunia.com/advisories/38903" source="SECUNIA">38903</ref>
      <ref url="http://secunia.com/advisories/38444" source="SECUNIA" adv="1">38444</ref>
      <ref url="http://moinmo.in/SecurityFixes" source="CONFIRM" adv="1">http://moinmo.in/SecurityFixes</ref>
      <ref url="http://moinmo.in/MoinMoinRelease1.8" source="CONFIRM">http://moinmo.in/MoinMoinRelease1.8</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES" source="CONFIRM">http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.5.0" edition="beta1" />
        <vers num="1.5.0" edition="beta2" />
        <vers num="1.5.0" edition="beta3" />
        <vers num="1.5.0" edition="beta4" />
        <vers num="1.5.0" edition="beta5" />
        <vers num="1.5.0" edition="beta6" />
        <vers num="1.5.0" edition="rc1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" edition="rc1" />
        <vers num="1.5.3" edition="rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" edition="rc1" />
        <vers num="1.5.5a" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.6.0" edition="beta1" />
        <vers num="1.6.0" edition="beta2" />
        <vers num="1.6.0" edition="rc1" />
        <vers num="1.6.0" edition="rc2" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.7.0" edition="beta1" />
        <vers num="1.7.0" edition="beta2" />
        <vers num="1.7.0" edition="rc1" />
        <vers num="1.7.0" edition="rc2" />
        <vers num="1.7.0" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers prev="1" num="1.8.6" />
        <vers num="1.9.0" />
        <vers num="1.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0670" published="2010-02-22" name="CVE-2010-0670" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path for Joomla! via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56523" source="XF">jquarks-unspecified-path-disclosure(56523)</ref>
      <ref url="http://www.iptechinside.com/labs/news/show/6" source="CONFIRM">http://www.iptechinside.com/labs/news/show/6</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iptechinside" name="com_jquarks">
        <vers num="0.2.2" />
        <vers prev="1" num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0671" published="2010-02-22" name="CVE-2010-0671" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a niusy action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38253" source="BID">38253</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509554/100/0/threaded" source="BUGTRAQ">20100216 Pogodny CMS SQL vulnerabilities</ref>
      <ref url="http://www.osvdb.org/62343" source="OSVDB">62343</ref>
      <ref url="http://www.exploit-db.com/exploits/11473" source="EXPLOIT-DB">11473</ref>
      <ref url="http://secunia.com/advisories/38571" source="SECUNIA" adv="1">38571</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/pogodnycms-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/pogodnycms-sql.txt</ref>
      <ref url="http://ariko-security.com/feb2010/ad439.html" source="MISC">http://ariko-security.com/feb2010/ad439.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michalin" name="kr_media_pogodny_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0672" published="2010-02-22" name="CVE-2010-0672" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via the orderlinks parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56256" source="XF">wsnguest-orderlinks-sql-injection(56256)</ref>
      <ref url="http://www.securityfocus.com/bid/38236" source="BID">38236</ref>
      <ref url="http://www.exploit-db.com/exploits/11436" source="EXPLOIT-DB">11436</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wsnguest102-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wsnguest102-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmastersite" name="wsn_guest">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0673" published="2010-02-22" name="CVE-2010-0673" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38239" source="BID">38239</ref>
      <ref url="http://www.exploit-db.com/exploits/11458" source="EXPLOIT-DB">11458</ref>
      <ref url="http://secunia.com/advisories/38579" source="SECUNIA" adv="1">38579</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wpcopperleaf-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wpcopperleaf-sql.txt</ref>
      <ref url="http://osvdb.org/62346" source="OSVDB">62346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="copperleaf" name="photolog">
        <vers num="0.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0674" published="2010-02-22" name="CVE-2010-0674" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56264" source="XF">statcountex-stats-info-disclosure(56264)</ref>
      <ref url="http://www.exploit-db.com/exploits/11434" source="EXPLOIT-DB">11434</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/statcountex-disclose.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/statcountex-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2enetworx" name="statcountex">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0675" published="2010-02-22" name="CVE-2010-0675" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38264" source="BID">38264</ref>
      <ref url="http://secunia.com/advisories/38597" source="SECUNIA" adv="1">38597</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/bgscms-xss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/bgscms-xss.txt</ref>
      <ref url="http://osvdb.org/62363" source="OSVDB">62363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bgsvetionik" name="bgs_cms">
        <vers num="2.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0676" published="2010-02-22" name="CVE-2010-0676" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in the RWCards (com_rwcards) component 3.0.18 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38267" source="BID">38267</ref>
      <ref url="http://secunia.com/advisories/38638" source="SECUNIA" adv="1">38638</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/joomlarwcards-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/joomlarwcards-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="weberr" name="com_rwcards">
        <vers num="3.0.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0677" published="2010-02-22" name="CVE-2010-0677" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11452" source="EXPLOIT-DB">11452</ref>
      <ref url="http://secunia.com/advisories/38581" source="SECUNIA" adv="1">38581</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/katalog-rfisql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/katalog-rfisql.txt</ref>
      <ref url="http://osvdb.org/62339" source="OSVDB">62339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katalog.hurricane" name="katalog_stron_hurricane">
        <vers num="1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0678" published="2010-02-22" name="CVE-2010-0678" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11452" source="EXPLOIT-DB">11452</ref>
      <ref url="http://secunia.com/advisories/38581" source="SECUNIA" adv="1">38581</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/katalog-rfisql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/katalog-rfisql.txt</ref>
      <ref url="http://osvdb.org/62340" source="OSVDB">62340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katalog.hurricane" name="katalog_stron_hurricane">
        <vers num="1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0679" published="2010-02-22" name="CVE-2010-0679" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument to the (1) SaveasMolFile and (2) ReadMolFile methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38225" source="BID">38225</ref>
      <ref url="http://www.security-assessment.com/files/advisories/2010-02-11_ChemviewX_Activex.pdf" source="MISC">http://www.security-assessment.com/files/advisories/2010-02-11_ChemviewX_Activex.pdf</ref>
      <ref url="http://www.exploit-db.com/exploits/11422" source="EXPLOIT-DB">11422</ref>
      <ref url="http://secunia.com/advisories/38523" source="SECUNIA" adv="1">38523</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/hyleoschemview-heap.rb.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/hyleoschemview-heap.rb.txt</ref>
      <ref url="http://packetstormsecurity.org/1002-advisories/chemviewx-overflow.txt" source="MISC">http://packetstormsecurity.org/1002-advisories/chemviewx-overflow.txt</ref>
      <ref url="http://osvdb.org/62276" source="OSVDB">62276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hyleos" name="chemview">
        <vers num="1.9.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0680" published="2010-02-22" name="CVE-2010-0680" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38237" source="BID">38237</ref>
      <ref url="http://www.exploit-db.com/exploits/11437" source="EXPLOIT-DB">11437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeuscms" name="zeuscms">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0681" published="2010-02-22" name="CVE-2010-0681" modified="2010-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11437" source="EXPLOIT-DB">11437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeuscms" name="zeuscms">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0682" published="2010-02-23" name="CVE-2010-0682" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://wordpress.org/development/2010/02/wordpress-2-9-2/" source="CONFIRM" patch="1" adv="1">http://wordpress.org/development/2010/02/wordpress-2-9-2/</ref>
      <ref url="https://core.trac.wordpress.org/ticket/11236" source="CONFIRM">https://core.trac.wordpress.org/ticket/11236</ref>
      <ref url="http://www.osvdb.org/62330" source="OSVDB">62330</ref>
      <ref url="http://tmacuk.co.uk/?p=180" source="MISC">http://tmacuk.co.uk/?p=180</ref>
      <ref url="http://secunia.com/advisories/42871" source="SECUNIA">42871</ref>
      <ref url="http://secunia.com/advisories/38592" source="SECUNIA" adv="1">38592</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052932.html" source="FEDORA">FEDORA-2010-19329</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052917.html" source="FEDORA">FEDORA-2010-19330</ref>
      <ref url="http://hakre.wordpress.com/2010/02/16/the-short-memory-of-wordpress-org-security/" source="MISC">http://hakre.wordpress.com/2010/02/16/the-short-memory-of-wordpress-org-security/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress">
        <vers num="2.9" />
        <vers num="2.9.1" edition="beta1" />
        <vers num="2.9.1" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0683" published="2010-02-25" name="CVE-2010-0683" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related to leveraging administrative credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tibco.com/services/support/advisories/adminstrator-advisory_20100223.jsp" source="CONFIRM" patch="1" adv="1">http://www.tibco.com/services/support/advisories/adminstrator-advisory_20100223.jsp</ref>
      <ref url="http://www.tibco.com/multimedia/security_advisory_administrator_tcm8-10685.txt" source="CONFIRM" patch="1" adv="1">http://www.tibco.com/multimedia/security_advisory_administrator_tcm8-10685.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0463" source="VUPEN" adv="1">ADV-2010-0463</ref>
      <ref url="http://www.securityfocus.com/bid/38396" source="BID">38396</ref>
      <ref url="http://secunia.com/advisories/38732" source="SECUNIA" adv="1">38732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tibco" name="administrator">
        <vers num="5.4.0" />
        <vers num="5.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0684" published="2010-04-05" name="CVE-2010-0684" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39119" source="BID" patch="1">39119</ref>
      <ref url="http://activemq.apache.org/activemq-531-release.html" source="CONFIRM" patch="1">http://activemq.apache.org/activemq-531-release.html</ref>
      <ref url="https://issues.apache.org/activemq/browse/AMQ-2625" source="CONFIRM">https://issues.apache.org/activemq/browse/AMQ-2625</ref>
      <ref url="https://issues.apache.org/activemq/browse/AMQ-2613" source="CONFIRM">https://issues.apache.org/activemq/browse/AMQ-2613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57397" source="XF">activemq-createdestination-xss(57397)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510419/100/0/threaded" source="BUGTRAQ">20100330 CVE-2010-0684: Apache ActiveMQ Persistent Cross-Site Scripting (XSS) Vulnerability</ref>
      <ref url="http://www.rajatswarup.com/CVE-2010-0684.txt" source="MISC">http://www.rajatswarup.com/CVE-2010-0684.txt</ref>
      <ref url="http://securitytracker.com/id?1023778" source="SECTRACK">1023778</ref>
      <ref url="http://secunia.com/advisories/39223" source="SECUNIA" adv="1">39223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="activemq">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="4.0" edition="m4" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="5.0.0" />
        <vers num="5.1.0" />
        <vers num="5.2.0" />
        <vers prev="1" num="5.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0685" published="2010-02-23" name="CVE-2010-0685" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstrated using the Dial application to process a crafted SIP INVITE message that adds an unintended outgoing channel leg.  NOTE: it could be argued that this is not a vulnerability in Asterisk, but a class of vulnerabilities that can occur in any program that uses this feature without the associated filtering functionality that is already available.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56397" source="XF">asterisk-dial-weak-security(56397)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0439" source="VUPEN" adv="1">ADV-2010-0439</ref>
      <ref url="http://www.securitytracker.com/id?1023637" source="SECTRACK">1023637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509608/100/0/threaded" source="BUGTRAQ">20100218 AST-2010-002: Dialplan injection vulnerability</ref>
      <ref url="http://svn.asterisk.org/svn/asterisk/branches/1.2/README-SERIOUSLY.bestpractices.txt" source="MISC">http://svn.asterisk.org/svn/asterisk/branches/1.2/README-SERIOUSLY.bestpractices.txt</ref>
      <ref url="http://secunia.com/advisories/39096" source="SECUNIA">39096</ref>
      <ref url="http://secunia.com/advisories/38641" source="SECUNIA" adv="1">38641</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html" source="FEDORA">FEDORA-2010-3724</ref>
      <ref url="http://downloads.digium.com/pub/security/AST-2010-002.html" source="CONFIRM" adv="1">http://downloads.digium.com/pub/security/AST-2010-002.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.0" edition="rc2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" edition="netsec" />
        <vers num="1.2.11" edition="netsec" />
        <vers num="1.2.12" edition="netsec" />
        <vers num="1.2.12.1" edition="netsec" />
        <vers num="1.2.13" edition="netsec" />
        <vers num="1.2.14" />
        <vers num="1.2.15" edition="netsec" />
        <vers num="1.2.16" edition="netsec" />
        <vers num="1.2.17" edition="netsec" />
        <vers num="1.2.18" edition="netsec" />
        <vers num="1.2.19" edition="netsec" />
        <vers num="1.2.2" edition="netsec" />
        <vers num="1.2.20" edition="netsec" />
        <vers num="1.2.21" edition="netsec" />
        <vers num="1.2.21.1" edition="netsec" />
        <vers num="1.2.22" edition="netsec" />
        <vers num="1.2.23" edition="netsec" />
        <vers num="1.2.24" edition="netsec" />
        <vers num="1.2.25" edition="netsec" />
        <vers num="1.2.26" edition="netsec" />
        <vers num="1.2.26.1" edition="netsec" />
        <vers num="1.2.26.2" edition="netsec" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.28.1" />
        <vers num="1.2.29" />
        <vers num="1.2.3" edition="netsec" />
        <vers num="1.2.30" />
        <vers num="1.2.30.1" />
        <vers num="1.2.30.2" />
        <vers num="1.2.30.3" />
        <vers num="1.2.30.4" />
        <vers num="1.2.31" />
        <vers num="1.2.31.1" />
        <vers num="1.2.32" />
        <vers num="1.2.33" />
        <vers num="1.2.34" />
        <vers num="1.2.35" />
        <vers num="1.2.36" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.15" />
        <vers num="1.4.16" />
        <vers num="1.4.17" />
        <vers num="1.4.18" />
        <vers num="1.4.19" />
        <vers num="1.4.2" />
        <vers num="1.4.20" />
        <vers num="1.4.21" />
        <vers num="1.4.22" />
        <vers num="1.4.23" />
        <vers num="1.4.24" />
        <vers num="1.4.25" />
        <vers num="1.4.26" />
        <vers num="1.4.27" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="b.1.3.2" edition="-" />
        <vers num="b.1.3.2" edition="-:business" />
        <vers num="b.1.3.3" edition="-" />
        <vers num="b.1.3.3" edition="-:business" />
        <vers num="b.2.2.0" edition="-" />
        <vers num="b.2.2.0" edition="-:business" />
        <vers num="b.2.2.1" edition="-" />
        <vers num="b.2.2.1" edition="-:business" />
        <vers num="b.2.3.1" edition="-" />
        <vers num="b.2.3.1" edition="-:business" />
        <vers num="b.2.3.2" edition="-" />
        <vers num="b.2.3.2" edition="-:business" />
        <vers num="b.2.3.3" edition="-" />
        <vers num="b.2.3.3" edition="-:business" />
        <vers num="b.2.3.4" edition="-" />
        <vers num="b.2.3.4" edition="-:business" />
        <vers num="b.2.3.5" edition="-" />
        <vers num="b.2.3.5" edition="-:business" />
        <vers num="b.2.3.6" edition="-" />
        <vers num="b.2.3.6" edition="-:business" />
        <vers num="b.2.5.0" edition="-" />
        <vers num="b.2.5.0" edition="-:business" />
        <vers num="b.2.5.1" edition="-" />
        <vers num="b.2.5.1" edition="-:business" />
        <vers num="b.2.5.2" edition="-" />
        <vers num="b.2.5.2" edition="-:business" />
        <vers num="b.2.5.3" edition="-" />
        <vers num="b.2.5.3" edition="-:business" />
        <vers num="c.1.0" edition="beta7" />
        <vers num="c.1.0" edition="beta7:business" />
        <vers num="c.1.0" edition="beta8" />
        <vers num="c.1.0" edition="beta8:business" />
        <vers num="c.1.6" edition="-" />
        <vers num="c.1.6" edition="-:business" />
        <vers num="c.1.6.1" edition="-" />
        <vers num="c.1.6.1" edition="-:business" />
        <vers num="c.1.6.2" edition="-" />
        <vers num="c.1.6.2" edition="-:business" />
        <vers num="c.1.8.0" edition="-" />
        <vers num="c.1.8.0" edition="-:business" />
        <vers num="c.1.8.1" edition="-" />
        <vers num="c.1.8.1" edition="-:business" />
        <vers num="c.2.3" edition="-" />
        <vers num="c.2.3" edition="-:business" />
        <vers num="c.3.0" edition="-" />
        <vers num="c.3.0" edition="-:business" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0686" published="2010-04-01" name="CVE-2010-0686" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0005.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0005.html</ref>
      <ref url="http://www.securityfocus.com/bid/39037" source="BID" patch="1">39037</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000086.html" source="MLIST" patch="1" adv="1">[security-announce] 20100329 VMSA-2010-0005 VMware products address vulnerabilities in WebAccess</ref>
      <ref url="http://www.securitytracker.com/id?1023769" source="SECTRACK">1023769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="esx_server">
        <vers num="3.0.3" />
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
      </prod>
      <prod vendor="vmware" name="virtualcenter">
        <vers num="2.0.2" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0688" published="2010-03-19" name="CVE-2010-0688" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59560" source="XF">orbitalviewer-ov-bo(59560)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0478" source="VUPEN" adv="1">ADV-2010-0478</ref>
      <ref url="http://www.securityfocus.com/bid/40985" source="BID">40985</ref>
      <ref url="http://www.securityfocus.com/bid/38436" source="BID">38436</ref>
      <ref url="http://www.osvdb.org/62580" source="OSVDB">62580</ref>
      <ref url="http://www.exploit-db.com/exploits/13940" source="EXPLOIT-DB">13940</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-011-orbital-viewer-orb-buffer-overflow/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-011-orbital-viewer-orb-buffer-overflow/</ref>
      <ref url="http://secunia.com/advisories/38720" source="SECUNIA" adv="1">38720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbitals" name="orbital_viewer">
        <vers num="1.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0689" published="2010-02-26" name="CVE-2010-0689" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/77.html

"CWE-77: Improper Sanitization of Special Elements used in a Command ('Command Injection')"</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56530" source="XF">datev-dvbsexecall-command-execution(56530)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0474" source="VUPEN">ADV-2010-0474</ref>
      <ref url="http://www.securityfocus.com/bid/38415" source="BID">38415</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509743/100/0/threaded" source="BUGTRAQ">20100225 NSOADV-2010-003: DATEV ActiveX Control remote command execution</ref>
      <ref url="http://www.datev.de/info-db/1080162" source="CONFIRM">http://www.datev.de/info-db/1080162</ref>
      <ref url="http://sotiriu.de/demos/videos/nso-2010-003.html" source="MISC">http://sotiriu.de/demos/videos/nso-2010-003.html</ref>
      <ref url="http://sotiriu.de/adv/NSOADV-2010-003.txt" source="MISC">http://sotiriu.de/adv/NSOADV-2010-003.txt</ref>
      <ref url="http://secunia.com/advisories/38716" source="SECUNIA" adv="1">38716</ref>
      <ref url="http://osvdb.org/62564" source="OSVDB">62564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datev" name="base_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0690" published="2010-02-23" name="CVE-2010-0690" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56226" source="XF">videogames-index-sql-injection(56226)</ref>
      <ref url="http://www.exploit-db.com/exploits/11409" source="EXPLOIT-DB">11409</ref>
      <ref url="http://secunia.com/advisories/38555" source="SECUNIA" adv="1">38555</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/videogamesrental-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/videogamesrental-sql.txt</ref>
      <ref url="http://osvdb.org/62295" source="OSVDB">62295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodityrentals" name="video_games_rentals">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0691" published="2010-02-23" name="CVE-2010-0691" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11445" source="EXPLOIT-DB">11445</ref>
      <ref url="http://secunia.com/advisories/38588" source="SECUNIA" adv="1">38588</ref>
      <ref url="http://osvdb.org/62329" source="OSVDB">62329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jtl-software" name="jtl-shop">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0692" published="2010-02-23" name="CVE-2010-0692" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38203" source="BID" patch="1">38203</ref>
      <ref url="http://www.iptechinside.com/labs/news/show/6" source="CONFIRM" patch="1" adv="1">http://www.iptechinside.com/labs/news/show/6</ref>
      <ref url="http://www.osvdb.org/62332" source="OSVDB">62332</ref>
      <ref url="http://secunia.com/advisories/38623" source="SECUNIA" adv="1">38623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iptechinside" name="com_jquarks">
        <vers num="0.2.2" />
        <vers num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0693" published="2010-02-23" name="CVE-2010-0693" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56223" source="XF" adv="1">trade-manager-products-sql-injection(56223)</ref>
      <ref url="http://www.exploit-db.com/exploits/11412" source="EXPLOIT-DB">11412</ref>
      <ref url="http://secunia.com/advisories/38556" source="SECUNIA" adv="1">38556</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/trademanager-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/trademanager-sql.txt</ref>
      <ref url="http://osvdb.org/62294" source="OSVDB">62294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodityrentals" name="trade_manager_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0694" published="2010-02-23" name="CVE-2010-0694" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55447" source="XF">perchagallery-index-sql-injection(55447)</ref>
      <ref url="http://www.securityfocus.com/bid/37642" source="BID">37642</ref>
      <ref url="http://www.exploit-db.com/exploits/11024" source="EXPLOIT-DB">11024</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlaperchagallery-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlaperchagallery-sql.txt</ref>
      <ref url="http://docs.joomla.org/Vulnerable_Extensions_List#New_format_Feed_Starts_Here" source="MISC">http://docs.joomla.org/Vulnerable_Extensions_List#New_format_Feed_Starts_Here</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchagallery">
        <vers prev="1" num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0695" published="2010-02-23" name="CVE-2010-0695" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38235" source="BID">38235</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/basiccms-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/basiccms-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="basic-cms" name="basic-cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0696" published="2010-02-23" name="CVE-2010-0696" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.joomlaworks.gr/content/view/77/34/" source="CONFIRM" patch="1" adv="1">http://www.joomlaworks.gr/content/view/77/34/</ref>
      <ref url="http://www.securityfocus.com/bid/38238" source="BID">38238</ref>
      <ref url="http://www.exploit-db.com/exploits/11447" source="EXPLOIT-DB">11447</ref>
      <ref url="http://secunia.com/advisories/38587" source="SECUNIA" adv="1">38587</ref>
      <ref url="http://osvdb.org/62331" source="OSVDB">62331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlaworks" name="jw_allvideos">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0697" published="2010-02-23" name="CVE-2010-0697" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38292" source="BID" patch="1">38292</ref>
      <ref url="http://drupal.org/node/717214" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/717214</ref>
      <ref url="http://drupal.org/node/711074" source="CONFIRM" patch="1">http://drupal.org/node/711074</ref>
      <ref url="http://drupal.org/node/711072" source="CONFIRM" patch="1">http://drupal.org/node/711072</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56351" source="XF">itweakupload-filenames-xss(56351)</ref>
      <ref url="http://secunia.com/advisories/38633" source="SECUNIA" adv="1">38633</ref>
      <ref url="http://osvdb.org/62405" source="OSVDB">62405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ilya_ivanchenko" name="itweak_upload">
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.x-dev" />
        <vers num="6.x-2.0" edition="rc1" />
        <vers num="6.x-2.1" edition="rc2" />
        <vers num="6.x-2.2" />
        <vers num="6.x-2.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0698" published="2010-02-23" name="CVE-2010-0698" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56406" source="XF">wsccms-login-sql-injection(56406)</ref>
      <ref url="http://www.securityfocus.com/bid/38335" source="BID">38335</ref>
      <ref url="http://www.exploit-db.com/exploits/11507" source="EXPLOIT-DB">11507</ref>
      <ref url="http://secunia.com/advisories/38698" source="SECUNIA" adv="1">38698</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wsccms-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wsccms-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dynamicsoft" name="wsc_cms">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0699" published="2010-02-23" name="CVE-2010-0699" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38701" source="SECUNIA" adv="1">38701</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/vss-xss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/vss-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videosearchscript" name="videosearchscript_pro">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0700" published="2010-02-23" name="CVE-2010-0700" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://zeroscience.mk/en/vulnerabilities/ZSL-2010-4926.php" source="MISC">http://zeroscience.mk/en/vulnerabilities/ZSL-2010-4926.php</ref>
      <ref url="http://zeroscience.mk/codes/wamp_xss.txt" source="MISC">http://zeroscience.mk/codes/wamp_xss.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56417" source="XF">wampserver-index-xss(56417)</ref>
      <ref url="http://www.securityfocus.com/bid/38357" source="BID">38357</ref>
      <ref url="http://secunia.com/advisories/38706" source="SECUNIA" adv="1">38706</ref>
      <ref url="http://osvdb.org/62481" source="OSVDB">62481</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wampserver" name="wampserver">
        <vers num="2.0i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0701" published="2010-02-23" name="CVE-2010-0701" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56237" source="XF">omnidocs-forcechangepassword-sql-injection(56237)</ref>
      <ref url="http://www.securityfocus.com/bid/38304" source="BID">38304</ref>
      <ref url="http://www.exploit-db.com/exploits/11393" source="EXPLOIT-DB">11393</ref>
      <ref url="http://secunia.com/advisories/38527" source="SECUNIA" adv="1">38527</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/omnidocs-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/omnidocs-sql.txt</ref>
      <ref url="http://osvdb.org/62403" source="OSVDB">62403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newgensoft" name="omnidocs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0702" published="2010-02-23" name="CVE-2010-0702" modified="2010-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56407" source="XF">trixbox-phonedirectory-sql-injection(56407)</ref>
      <ref url="http://www.securityfocus.com/bid/38323" source="BID">38323</ref>
      <ref url="http://www.exploit-db.com/exploits/11508" source="EXPLOIT-DB">11508</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/tribox-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/tribox-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fonality" name="trixbox">
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0703" published="2010-02-23" name="CVE-2010-0703" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56420" source="XF">portwise-reloadframe-xss(56420)</ref>
      <ref url="http://www.securityfocus.com/bid/38308" source="BID">38308</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509584/100/0/threaded" source="BUGTRAQ">20100217 Cross-Site Scriting on Portwise SSL VPN v4.6</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-04" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-04</ref>
      <ref url="http://secunia.com/advisories/38627" source="SECUNIA" adv="1">38627</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/PR09-04.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/PR09-04.txt</ref>
      <ref url="http://osvdb.org/62482" source="OSVDB">62482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="portwise" name="ssl_vpn">
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0704" published="2010-02-24" name="CVE-2010-0704" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM05829" source="AIXAPAR" adv="1">PM05829</ref>
      <ref url="http://secunia.com/advisories/38574" source="SECUNIA" adv="1">38574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="6.0.1.5" edition="wp6015_008_01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0705" published="2010-02-25" name="CVE-2010-0705" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0449" source="VUPEN" adv="1">ADV-2010-0449</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2010-003.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2010-003.txt</ref>
      <ref url="http://www.securitytracker.com/id?1023644" source="SECTRACK">1023644</ref>
      <ref url="http://www.securityfocus.com/bid/38363" source="BID">38363</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509710/100/0/threaded" source="BUGTRAQ">20100223 [TKADV2010-003] avast! 4.8 and 5.0 aavmker4.sys Kernel Memory Corruption</ref>
      <ref url="http://secunia.com/advisories/38689" source="SECUNIA" adv="1">38689</ref>
      <ref url="http://secunia.com/advisories/38677" source="SECUNIA" adv="1">38677</ref>
      <ref url="http://osvdb.org/62510" source="OSVDB">62510</ref>
      <ref url="http://forum.avast.com/index.php?topic=55484.0" source="CONFIRM" adv="1">http://forum.avast.com/index.php?topic=55484.0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avast" name="avast_antivirus_home">
        <vers num="4.8.1169" edition="" />
        <vers num="4.8.1169" edition=":windows" />
        <vers num="4.8.1195" edition="" />
        <vers num="4.8.1195" edition=":windows" />
        <vers num="4.8.1201" edition="" />
        <vers num="4.8.1201" edition=":windows" />
        <vers num="4.8.1227" edition="" />
        <vers num="4.8.1227" edition=":windows" />
        <vers num="4.8.1229" edition="" />
        <vers num="4.8.1229" edition=":windows" />
        <vers num="4.8.1282" edition="" />
        <vers num="4.8.1282" edition=":windows" />
        <vers num="4.8.1290" edition="" />
        <vers num="4.8.1290" edition=":windows" />
        <vers num="4.8.1296" edition="" />
        <vers num="4.8.1296" edition=":windows" />
        <vers num="4.8.1335" edition="" />
        <vers num="4.8.1335" edition=":windows" />
        <vers num="4.8.1351" edition="" />
        <vers num="4.8.1351" edition=":windows" />
        <vers num="4.8.1368.0" edition="" />
        <vers num="4.8.1368.0" edition=":windows" />
        <vers prev="1" num="5.0.396.0" edition="" />
        <vers prev="1" num="5.0.396.0" edition=":windows" />
      </prod>
      <prod vendor="avast" name="avast_antivirus_professional">
        <vers num="4.8.1169" edition="" />
        <vers num="4.8.1169" edition=":windows" />
        <vers num="4.8.1195" edition="" />
        <vers num="4.8.1195" edition=":windows" />
        <vers num="4.8.1201" edition="" />
        <vers num="4.8.1201" edition=":windows" />
        <vers num="4.8.1227" edition="" />
        <vers num="4.8.1227" edition=":windows" />
        <vers num="4.8.1229" edition="" />
        <vers num="4.8.1229" edition=":windows" />
        <vers num="4.8.1282" edition="" />
        <vers num="4.8.1282" edition=":windows" />
        <vers num="4.8.1290" edition="" />
        <vers num="4.8.1290" edition=":windows" />
        <vers num="4.8.1296" edition="" />
        <vers num="4.8.1296" edition=":windows" />
        <vers num="4.8.1335" edition="" />
        <vers num="4.8.1335" edition=":windows" />
        <vers num="4.8.1351" edition="" />
        <vers num="4.8.1351" edition=":windows" />
        <vers num="4.8.1356.0" />
        <vers num="4.8.1368.0" edition="" />
        <vers num="4.8.1368.0" edition=":windows" />
        <vers prev="1" num="5.0.396.0" edition="" />
        <vers prev="1" num="5.0.396.0" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0706" published="2010-02-25" name="CVE-2010-0706" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the login/prompt component in Subex Nikira Fraud Management System allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56393" source="XF">nfms-message-xss(56393)</ref>
      <ref url="http://www.securityfocus.com/bid/38311" source="BID">38311</ref>
      <ref url="http://www.packetstormsecurity.org/1002-exploits/nikara-xss.txt" source="MISC">http://www.packetstormsecurity.org/1002-exploits/nikara-xss.txt</ref>
      <ref url="http://secunia.com/advisories/38564" source="SECUNIA" adv="1">38564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="subexworld" name="nikira_fraud_management_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0707" published="2010-02-25" name="CVE-2010-0707" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an administrator for requests that create new administrative users.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56410" source="XF">timeclock-adduser-csrf(56410)</ref>
      <ref url="http://www.exploit-db.com/exploits/11516" source="EXPLOIT-DB">11516</ref>
      <ref url="http://secunia.com/advisories/38662" source="SECUNIA" adv="1">38662</ref>
      <ref url="http://osvdb.org/62478" source="OSVDB">62478</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timeclock-software" name="employee_timeclock_software">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0708" published="2010-02-25" name="CVE-2010-0708" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-275711-1" source="SUNALERT" patch="1" adv="1">275711</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-143884-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-143884-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56603" source="XF">jsds-nsslapd-slapd-dos(56603)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021788.1-1" source="SUNALERT">1021788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="5.2" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:enterprise" />
        <vers num="6.1" edition="-" />
        <vers num="6.1" edition="-:enterprise" />
        <vers num="6.2" edition="-" />
        <vers num="6.2" edition="-:enterprise" />
        <vers num="6.3" edition="-" />
        <vers num="6.3" edition="-:enterprise" />
        <vers num="6.3.1" edition="-" />
        <vers num="6.3.1" edition="-:enterprise" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0709" published="2010-02-25" name="CVE-2010-0709" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authentication of users or administrators for requests that change the email address or password via the user action to index.php, and (2) hijack the authentication of the administrator for requests that create a new user via the admin/modules/user/new action to limny/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.limny.org/" source="CONFIRM" patch="1" adv="1">http://www.limny.org/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56318" source="XF">limny-admin-csrf(56318)</ref>
      <ref url="http://www.exploit-db.com/exploits/11478" source="EXPLOIT-DB">11478</ref>
      <ref url="http://www.exploit-db.com/exploits/11477" source="EXPLOIT-DB">11477</ref>
      <ref url="http://secunia.com/advisories/38616" source="SECUNIA" adv="1">38616</ref>
      <ref url="http://osvdb.org/62389" source="OSVDB">62389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limny" name="limny">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0710" published="2010-02-25" name="CVE-2010-0710" modified="2010-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the newsid parameter when the sec parameter is 26.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38596" source="SECUNIA" adv="1">38596</ref>
      <ref url="http://osvdb.org/62358" source="OSVDB">62358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspcodecms" name="aspcode_cms">
        <vers num="1.5.8" />
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0711" published="2010-02-25" name="CVE-2010-0711" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other versions, allows remote attackers to hijack the authentication of an administrator for requests that (1) delete users via the delete action in the ma2 parameter or (2) create administrators via the update action in the ma2 parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38596" source="SECUNIA" adv="1">38596</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/aspcodecms-xssxsrf.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/aspcodecms-xssxsrf.txt</ref>
      <ref url="http://osvdb.org/62357" source="OSVDB">62357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspcodecms" name="aspcode_cms">
        <vers num="1.5.8" />
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0712" published="2010-02-26" name="CVE-2010-0712" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary SQL commands via the (1) severity, (2) state, (3) filter, (4) offset, and (5) count parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55670" source="XF">zenoss-getjsoneventsinfo-sql-injection(55670)</ref>
      <ref url="http://www.zenoss.com/news/SQL-Injection-and-Cross-Site-Forgery-in-Zenoss-Core-Corrected.html" source="CONFIRM" adv="1">http://www.zenoss.com/news/SQL-Injection-and-Cross-Site-Forgery-in-Zenoss-Core-Corrected.html</ref>
      <ref url="http://www.securityfocus.com/bid/37802" source="BID">37802</ref>
      <ref url="http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/" source="MISC">http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/</ref>
      <ref url="http://secunia.com/advisories/38195" source="SECUNIA" adv="1">38195</ref>
      <ref url="http://osvdb.org/61804" source="OSVDB">61804</ref>
      <ref url="http://dev.zenoss.org/trac/changeset/15257" source="MISC" adv="1">http://dev.zenoss.org/trac/changeset/15257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zenoss" name="zenoss">
        <vers num="2.3.0" />
        <vers num="2.3.3" />
        <vers num="2.4.0" />
        <vers num="2.4.2" />
        <vers prev="1" num="2.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0713" published="2010-02-26" name="CVE-2010-0713" modified="2010-03-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator for (1) requests that reset user passwords via zport/dmd/ZenUsers/admin, and (2) requests that change user commands, which allows for remote execution of system commands via zport/dmd/userCommands/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zenoss.com/news/SQL-Injection-and-Cross-Site-Forgery-in-Zenoss-Core-Corrected.html" source="CONFIRM" adv="1">http://www.zenoss.com/news/SQL-Injection-and-Cross-Site-Forgery-in-Zenoss-Core-Corrected.html</ref>
      <ref url="http://www.securityfocus.com/bid/37843" source="BID">37843</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508982/100/0/threaded" source="BUGTRAQ">20100116 Zenoss Multiple Admin CSRF</ref>
      <ref url="http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/" source="MISC">http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/</ref>
      <ref url="http://secunia.com/advisories/38195" source="SECUNIA" adv="1">38195</ref>
      <ref url="http://osvdb.org/61805" source="OSVDB">61805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zenoss" name="zenoss">
        <vers num="2.3.0" />
        <vers num="2.3.3" />
        <vers num="2.4.0" />
        <vers num="2.4.2" />
        <vers prev="1" num="2.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0714" published="2010-02-26" name="CVE-2010-0714" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21421469" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21421469</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56508" source="XF">ibm-login-xss(56508)</ref>
      <ref url="http://www.securitytracker.com/id?1023660" source="SECTRACK">1023660</ref>
      <ref url="http://www.securityfocus.com/bid/38412" source="BID">38412</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509744/100/0/threaded" source="BUGTRAQ">20100225 Hacktics Advisory Feb10: XSS in IBM WebSphere Portal &amp; Lotus WCM</ref>
      <ref url="http://www.hacktics.com/content/advisories/AdvIBM20100224.html" source="MISC">http://www.hacktics.com/content/advisories/AdvIBM20100224.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_quickr">
        <vers num="8.0" />
        <vers num="8.0.0.2" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.1.1" />
      </prod>
      <prod vendor="ibm" name="lotus_web_content_management">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
      <prod vendor="ibm" name="lotus_workplace_web_content_management">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0715" published="2010-02-26" name="CVE-2010-0715" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1, 8.1.1, and 8.1.1.1 for WebSphere Portal; allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21421469" source="MISC" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21421469</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56602" source="XF">ibm-login-phishing(56602)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509744/100/0/threaded" source="BUGTRAQ">20100225 Hacktics Advisory Feb10: XSS in IBM WebSphere Portal &amp; Lotus WCM</ref>
      <ref url="http://www.hacktics.com/content/advisories/AdvIBM20100224.html" source="MISC">http://www.hacktics.com/content/advisories/AdvIBM20100224.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_quickr">
        <vers num="8.0" />
        <vers num="8.0.0.2" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.1.1" />
      </prod>
      <prod vendor="ibm" name="lotus_web_content_management">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
      <prod vendor="ibm" name="lotus_workplace_web_content_management">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.4" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.6" />
        <vers num="6.0.1.7" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0716" published="2010-02-26" name="CVE-2010-0716" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56597" source="XF">sharepoint-aspx-xss(56597)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509683/100/0/threaded" source="BUGTRAQ">20100222 Hacktics Advisory Feb10: Persistent XSS in Microsoft SharePoint Portal</ref>
      <ref url="http://www.hacktics.com/content/advisories/AdvMS20100222.html" source="MISC">http://www.hacktics.com/content/advisories/AdvMS20100222.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers prev="1" num="2007" edition="sp1" />
        <vers prev="1" num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0717" published="2010-02-26" name="CVE-2010-0717" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56595" source="XF">moinmoin-cfgpackagepages-unspecified(56595)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0600" source="VUPEN">ADV-2010-0600</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/15/2" source="MLIST">[oss-security] 20100215 CVE Request -- MoinMoin -- 1.8.7</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2014" source="DEBIAN">DSA-2014</ref>
      <ref url="http://secunia.com/advisories/38903" source="SECUNIA">38903</ref>
      <ref url="http://moinmo.in/MoinMoinRelease1.8" source="CONFIRM">http://moinmo.in/MoinMoinRelease1.8</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES" source="CONFIRM">http://hg.moinmo.in/moin/1.8/raw-file/1.8.7/docs/CHANGES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.5.0" edition="beta1" />
        <vers num="1.5.0" edition="beta2" />
        <vers num="1.5.0" edition="beta3" />
        <vers num="1.5.0" edition="beta4" />
        <vers num="1.5.0" edition="beta5" />
        <vers num="1.5.0" edition="beta6" />
        <vers num="1.5.0" edition="rc1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" edition="rc1" />
        <vers num="1.5.3" edition="rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" edition="rc1" />
        <vers num="1.5.5a" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.6.0" edition="beta1" />
        <vers num="1.6.0" edition="beta2" />
        <vers num="1.6.0" edition="rc1" />
        <vers num="1.6.0" edition="rc2" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.7.0" edition="beta1" />
        <vers num="1.7.0" edition="beta2" />
        <vers num="1.7.0" edition="rc1" />
        <vers num="1.7.0" edition="rc2" />
        <vers num="1.7.0" edition="rc3" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers prev="1" num="1.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0718" published="2010-02-26" name="CVE-2010-0718" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56435" source="XF">win-mediaplayer-mpg-bo(56435)</ref>
      <ref url="http://www.exploit-db.com/exploits/11531" source="EXPLOIT-DB">11531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="11.0.5721.5145" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0719" published="2010-02-26" name="CVE-2010-0719" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56591" source="XF">ms-win-api-dos(56591)</ref>
      <ref url="http://www.scmagazineus.com/malta-researchers-find-windows-bug-that-crashes-pcs/article/164439/" source="MISC">http://www.scmagazineus.com/malta-researchers-find-windows-bug-that-crashes-pcs/article/164439/</ref>
      <ref url="http://securitytracker.com/id?1023656" source="SECTRACK">1023656</ref>
      <ref url="http://osvdb.org/62660" source="OSVDB">62660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="-" edition="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0720" published="2010-02-26" name="CVE-2010-0720" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56330" source="XF">erotikauktionshaus-news-sql-injection(56330)</ref>
      <ref url="http://www.osvdb.org/62369" source="OSVDB">62369</ref>
      <ref url="http://www.exploit-db.com/exploits/11489" source="EXPLOIT-DB">11489</ref>
      <ref url="http://secunia.com/advisories/38614" source="SECUNIA" adv="1">38614</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/erotik-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/erotik-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2009/10/21/erotik-auktionshaus-sql-injection-news-php/" source="MISC">http://4004securityproject.wordpress.com/2009/10/21/erotik-auktionshaus-sql-injection-news-php/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemsoftware" name="erotik_auktionshaus">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0721" published="2010-02-26" name="CVE-2010-0721" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56332" source="XF">auktionshausgelb-news-sql-injection(56332)</ref>
      <ref url="http://www.exploit-db.com/exploits/11488" source="EXPLOIT-DB">11488</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/auktionshausgelb-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/auktionshausgelb-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemsoftware" name="auktionshaus_gelb">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0722" published="2010-02-26" name="CVE-2010-0722" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56478" source="XF">phpauktionpro-news-sql-injection(56478)</ref>
      <ref url="http://www.securityfocus.com/bid/38371" source="BID">38371</ref>
      <ref url="http://www.exploit-db.com/exploits/11547" source="EXPLOIT-DB">11547</ref>
      <ref url="http://secunia.com/advisories/38679" source="SECUNIA" adv="1">38679</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/02/22/php-auktion-pro-sql-injection-news-php/" source="MISC">http://4004securityproject.wordpress.com/2010/02/22/php-auktion-pro-sql-injection-news-php/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhproducts" name="php_auktion_pro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0723" published="2010-02-26" name="CVE-2010-0723" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56446" source="XF">eroauktion-news-sql-injection(56446)</ref>
      <ref url="http://www.exploit-db.com/exploits/11522" source="EXPLOIT-DB">11522</ref>
      <ref url="http://www.exploit-db.com/exploits/11521" source="EXPLOIT-DB">11521</ref>
      <ref url="http://secunia.com/advisories/38666" source="SECUNIA" adv="1">38666</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/eroauktion2010-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/eroauktion2010-sql.txt</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/eroauktion20-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/eroauktion20-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-v-2-0-sql-injection-news-php/" source="MISC">http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-v-2-0-sql-injection-news-php/</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-2010-sql-injection-news-php/" source="MISC">http://4004securityproject.wordpress.com/2010/02/21/ero-auktion-2010-sql-injection-news-php/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhproducts" name="ero_auktion">
        <vers num="2.0" />
        <vers num="2010" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0724" published="2010-02-26" name="CVE-2010-0724" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0443" source="VUPEN" adv="1">ADV-2010-0443</ref>
      <ref url="http://www.securityfocus.com/bid/38426" source="BID">38426</ref>
      <ref url="http://www.exploit-db.com/exploits/11524" source="EXPLOIT-DB">11524</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/arabcart-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/arabcart-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhd_zaher_ghaibeh" name="arab_cart">
        <vers num="1.0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0725" published="2010-02-26" name="CVE-2010-0725" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0443" source="VUPEN" adv="1">ADV-2010-0443</ref>
      <ref url="http://www.securityfocus.com/bid/38426" source="BID">38426</ref>
      <ref url="http://www.exploit-db.com/exploits/11524" source="EXPLOIT-DB">11524</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/arabcart-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/arabcart-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhd_zaher_ghaibeh" name="arab_cart">
        <vers num="1.0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0726" published="2010-03-02" name="CVE-2010-0726" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the tb-send.rb (TrackBack transmission) plugin in tDiary 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly related to the (1) plugin_tb_url and (2) plugin_tb_excerpt parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.tdiary.org/20100225.html" source="CONFIRM" patch="1" adv="1">http://www.tdiary.org/20100225.html</ref>
      <ref url="http://www.securityfocus.com/bid/38413" source="BID" patch="1">38413</ref>
      <ref url="http://tdiary.svn.sourceforge.net/viewvc/tdiary/branches/Stable-2_2/plugin/tb-send.rb?r1=3238&amp;r2=3573" source="MISC">http://tdiary.svn.sourceforge.net/viewvc/tdiary/branches/Stable-2_2/plugin/tb-send.rb?r1=3238&amp;r2=3573</ref>
      <ref url="http://secunia.com/advisories/38742" source="SECUNIA" adv="1">38742</ref>
      <ref url="http://osvdb.org/62562" source="OSVDB">62562</ref>
      <ref url="http://jvndb.jvn.jp/jvndb/JVNDB-2010-000005" source="JVNDB">JVNDB-2010-000005</ref>
      <ref url="http://jvn.jp/en/jp/JVN73331060/index.html" source="JVN">JVN#73331060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tdiary" name="tdiary">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.1.1" />
        <vers num="2.1.4.2006-11-15" />
        <vers prev="1" num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0727" published="2010-03-16" name="CVE-2010-0727" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=570863" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=570863</ref>
      <ref url="http://lkml.org/lkml/2010/3/11/269" source="MLIST" patch="1">[linux-kernel] 20100311 [PATCH 3/3] GFS2: Skip check for mandatory locks when unlocking</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0521.html" source="REDHAT">RHSA-2010:0521</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0380.html" source="REDHAT">RHSA-2010:0380</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0330.html" source="REDHAT">RHSA-2010:0330</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/12/1" source="MLIST">[oss-security] 20100312 CVE-2010-0727 kernel: gfs/gfs2 locking code DoS flaw</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:066" source="MANDRIVA">MDVSA-2010:066</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.34-rc1-next-20100312.bz2" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/next/patch-v2.6.34-rc1-next-20100312.bz2</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://securitytracker.com/id?1023809" source="SECTRACK">1023809</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11392" source="OVAL">oval:org.mitre.oval:def:11392</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33" edition="rc7" />
        <vers num="2.6.33" edition="rc8" />
        <vers num="2.6.33.1" />
        <vers prev="1" num="2.6.34" edition="rc1" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="5" />
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0728" published="2010-03-10" name="CVE-2010-0728" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=7222" source="CONFIRM">https://bugzilla.samba.org/show_bug.cgi?id=7222</ref>
      <ref url="http://www.samba.org/samba/security/CVE-2010-0728" source="CONFIRM" adv="1">http://www.samba.org/samba/security/CVE-2010-0728</ref>
      <ref url="http://www.samba.org/samba/history/samba-3.5.1.html" source="CONFIRM">http://www.samba.org/samba/history/samba-3.5.1.html</ref>
      <ref url="http://www.samba.org/samba/history/samba-3.4.7.html" source="CONFIRM">http://www.samba.org/samba/history/samba-3.4.7.html</ref>
      <ref url="http://www.samba.org/samba/history/samba-3.3.12.html" source="CONFIRM">http://www.samba.org/samba/history/samba-3.3.12.html</ref>
      <ref url="http://lists.samba.org/archive/samba-announce/2010/000211.html" source="MLIST" adv="1">[samba-announce] 20100308 Security problem with Samba on Linux - affects 3.5.0, 3.4.6 and 3.3.11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.3.11" />
        <vers num="3.4.6" />
        <vers num="3.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0729" published="2010-03-16" name="CVE-2010-0729" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572007" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572007</ref>
      <ref url="http://www.securityfocus.com/bid/38702" source="BID">38702</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0394.html" source="REDHAT">RHSA-2010:0394</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/12/2" source="MLIST">[oss-security] 20100312 CVE-2010-0729 kernel: ia64: ptrace: peek_or_poke requests miss ptrace_check_attach()</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100090459" source="CONFIRM">http://support.avaya.com/css/P8/documents/100090459</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8687" source="OVAL">oval:org.mitre.oval:def:8687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0730" published="2010-05-12" name="CVE-2010-0730" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation.</descript>
      <descript source="nvd">Per: http://secunia.com/advisories/39649

'Successful exploitation requires a 32bit system and access to an MMIO region.'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0398.html" source="REDHAT" patch="1" adv="1">RHSA-2010:0398</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572971" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572971</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39979" source="BID">39979</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/07/1" source="MLIST">[oss-security] 20100507 CVE-2010-0730 xen: emulator instruction decoding inconsistency</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100088287" source="CONFIRM">http://support.avaya.com/css/P8/documents/100088287</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39649" source="SECUNIA" adv="1">39649</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11430" source="OVAL">oval:org.mitre.oval:def:11430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="enterprise_linux">
        <vers num="5" edition="" />
        <vers num="5" edition=":server" />
        <vers num="5" edition=":client" />
        <vers num="5" edition="ga" />
        <vers num="5" edition="ga:client" />
        <vers num="5" edition="ga:server" />
        <vers num="5.0" />
      </prod>
      <prod vendor="redhat" name="enterprise_linux_desktop">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0731" published="2010-03-26" name="CVE-2010-0731" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The gnutls_x509_crt_get_serial function in the GnuTLS library before 1.2.1, when running on big-endian, 64-bit platforms, calls the asn1_read_value with a pointer to the wrong data type and the wrong length value, which allows remote attackers to bypass the certificate revocation list (CRL) check and cause a stack-based buffer overflow via a crafted X.509 certificate, related to extraction of a serial number.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/4230

"Please note that the problem was solved for GnuTLS 1.2.1, released on
2005-04-04.  Also, 32-bit platforms are not affected.  I have added
information about this on

http://www.gnu.org/software/gnutls/security.html

so that it contains the complete list of known security flaws.  I'm
using the keyword GNUTLS-SA-2010-1 for this."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0713" source="VUPEN" patch="1" adv="1">ADV-2010-0713</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=573028" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=573028</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1054" source="VUPEN">ADV-2010-1054</ref>
      <ref url="http://www.securityfocus.com/bid/38959" source="BID">38959</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0167.html" source="REDHAT">RHSA-2010:0167</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:089" source="MANDRIVA">MDVSA-2010:089</ref>
      <ref url="http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/4230" source="CONFIRM">http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/4230</ref>
      <ref url="http://secunia.com/advisories/39127" source="SECUNIA">39127</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9759" source="OVAL">oval:org.mitre.oval:def:9759</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
        <vers num="1.0.20" />
        <vers num="1.0.21" />
        <vers num="1.0.22" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22" />
        <vers num="1.1.23" />
        <vers prev="1" num="1.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0732" published="2010-03-19" name="CVE-2010-0732" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances and consequently allows physically proximate attackers to bypass screen locking and access an unattended workstation by pressing the Enter key many times.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=565527" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=565527</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=598476" source="CONFIRM" patch="1">https://bugzilla.gnome.org/show_bug.cgi?id=598476</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/05/2" source="MLIST" patch="1">[oss-security] 20100305 Re: CVE Request: gnome-screensaver termination by pressing "Enter"</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0" source="CONFIRM" patch="1">http://git.gnome.org/browse/gnome-screensaver/commit/?id=ab08cc93f2dc6223c8c00bfa1ca4f2d89069dbe0</ref>
      <ref url="https://bugs.edge.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/446395" source="CONFIRM">https://bugs.edge.launchpad.net/ubuntu/+source/gnome-screensaver/+bug/446395</ref>
      <ref url="http://www.securityfocus.com/bid/38211" source="BID">38211</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/16/9" source="MLIST">[oss-security] 20100316 Re: Re: CVE Request: gnome-screensaver termination by pressing "Enter"</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/12/1" source="MLIST">[oss-security] 20100212 CVE Request: gnome-screensaver termination by pressing "Enter"</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:109" source="MANDRIVA">MDVSA-2010:109</ref>
      <ref url="http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-2-Update-928580.html" source="MISC">http://www.heise.de/newsticker/meldung/Gnome-Bildschirmsperre-in-OpenSuse-Linux-wirkungslos-2-Update-928580.html</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://git.gnome.org/browse/gtk+/commit/?id=0748cf563d0d0d03001a62589f13be16a8ec06c1" source="CONFIRM">http://git.gnome.org/browse/gtk+/commit/?id=0748cf563d0d0d03001a62589f13be16a8ec06c1</ref>
      <ref url="http://git.gnome.org/browse/gnome-screensaver/commit/?h=gnome-2-28&amp;id=98f8a22412cf388217fd5b88915eadd274d68520" source="CONFIRM">http://git.gnome.org/browse/gnome-screensaver/commit/?h=gnome-2-28&amp;id=98f8a22412cf388217fd5b88915eadd274d68520</ref>
      <ref url="http://ftp.gnome.org/pub/gnome/sources/gtk+/2.18/gtk+-2.18.5.news" source="CONFIRM">http://ftp.gnome.org/pub/gnome/sources/gtk+/2.18/gtk+-2.18.5.news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtk" name="gtk+">
        <vers prev="1" num="2.18.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0733" published="2010-03-19" name="CVE-2010-0733" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=546621" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=546621</ref>
      <ref url="http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54" source="CONFIRM" patch="1">http://git.postgresql.org/gitweb?p=postgresql.git;a=commit;h=64b057e6823655fb6c5d1f24a28f236b94dd6c54</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1197" source="VUPEN">ADV-2010-1197</ref>
      <ref url="http://www.securityfocus.com/bid/38619" source="BID">38619</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0429.html" source="REDHAT">RHSA-2010:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0428.html" source="REDHAT">RHSA-2010:0428</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0427.html" source="REDHAT">RHSA-2010:0427</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/16/10" source="MLIST">[oss-security] 20100316 Re: CVE Request: postgresql integer overflow in hash table size calculation</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/09/2" source="MLIST">[oss-security] 20100309 CVE Request: postgresql integer overflow in hash table size calculation</ref>
      <ref url="http://secunia.com/advisories/39820" source="SECUNIA">39820</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10691" source="OVAL">oval:org.mitre.oval:def:10691</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2009-10/msg00310.php" source="MLIST">[pgsql-bugs] 20091030 Re: BUG #5145: Complex query with lots of LEFT JOIN causes segfault</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2009-10/msg00289.php" source="MLIST">[pgsql-bugs] 20091029 Re: BUG #5145: Complex query with lots of LEFT JOIN causes segfault</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2009-10/msg00287.php" source="MLIST">[pgsql-bugs] 20091029 Re: BUG #5145: Complex query with lots of LEFT JOIN causes segfault</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php" source="MLIST">[pgsql-bugs] 20091028 BUG #5145: Complex query with lots of LEFT JOIN causes segfault</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.0" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.11" />
        <vers num="8.0.12" />
        <vers num="8.0.13" />
        <vers num="8.0.14" />
        <vers num="8.0.15" />
        <vers num="8.0.16" />
        <vers num="8.0.17" />
        <vers num="8.0.18" />
        <vers num="8.0.19" />
        <vers num="8.0.2" />
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.0.23" />
        <vers num="8.0.3" />
        <vers num="8.0.317" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.10" />
        <vers num="8.1.11" />
        <vers num="8.1.12" />
        <vers num="8.1.13" />
        <vers num="8.1.14" />
        <vers num="8.1.15" />
        <vers num="8.1.16" />
        <vers num="8.1.17" />
        <vers num="8.1.18" />
        <vers num="8.1.19" />
        <vers num="8.1.2" />
        <vers num="8.1.20" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8" />
        <vers num="8.1.9" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.10" />
        <vers num="8.2.11" />
        <vers num="8.2.12" />
        <vers num="8.2.13" />
        <vers num="8.2.14" />
        <vers num="8.2.15" />
        <vers num="8.2.16" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.2.8" />
        <vers num="8.2.9" />
        <vers num="8.3" />
        <vers num="8.3.1" />
        <vers num="8.3.10" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.3.7" />
        <vers num="8.3.8" />
        <vers num="8.3.9" />
        <vers num="8.4" />
        <vers prev="1" num="8.4.1" />
        <vers num="8.5" edition="alpha1" />
        <vers num="8.5" edition="alpha2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0734" published="2010-03-19" name="CVE-2010-0734" modified="2011-10-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/16/11" source="MLIST" patch="1">[oss-security] 20100316 Re: CVE Request -- cURL/libCURL 7.20.0</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/09/1" source="MLIST" patch="1">[oss-security] 20100309 Re: CVE Request -- cURL/libCURL 7.20.0</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/09/5" source="MLIST" patch="1">[oss-security] 20100209 CVE Request -- cURL/libCURL 7.20.0</ref>
      <ref url="http://curl.haxx.se/libcurl-contentencoding.patch" source="CONFIRM" patch="1">http://curl.haxx.se/libcurl-contentencoding.patch</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=563220" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=563220</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0725" source="VUPEN">ADV-2010-0725</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0660" source="VUPEN">ADV-2010-0660</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0602" source="VUPEN">ADV-2010-0602</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0571" source="VUPEN">ADV-2010-0571</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1158-1" source="UBUNTU">USN-1158-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514490/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0072-1 curl</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0329.html" source="REDHAT">RHSA-2010:0329</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:062" source="MANDRIVA">MDVSA-2010:062</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2023" source="DEBIAN">DSA-2023</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2010-0072" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2010-0072</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100081819" source="CONFIRM">http://support.avaya.com/css/P8/documents/100081819</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://secunia.com/advisories/45047" source="SECUNIA">45047</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/39734" source="SECUNIA">39734</ref>
      <ref url="http://secunia.com/advisories/39087" source="SECUNIA">39087</ref>
      <ref url="http://secunia.com/advisories/38981" source="SECUNIA">38981</ref>
      <ref url="http://secunia.com/advisories/38843" source="SECUNIA">38843</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6756" source="OVAL">oval:org.mitre.oval:def:6756</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10760" source="OVAL">oval:org.mitre.oval:def:10760</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037143.html" source="FEDORA">FEDORA-2010-2720</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036744.html" source="FEDORA">FEDORA-2010-2762</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://curl.haxx.se/docs/security.html#20100209" source="CONFIRM" adv="1">http://curl.haxx.se/docs/security.html#20100209</ref>
      <ref url="http://curl.haxx.se/docs/adv_20100209.html" source="CONFIRM" adv="1">http://curl.haxx.se/docs/adv_20100209.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="libcurl">
        <vers num="7.10.5" />
        <vers num="7.10.6" />
        <vers num="7.10.7" />
        <vers num="7.10.8" />
        <vers num="7.11.0" />
        <vers num="7.11.1" />
        <vers num="7.11.2" />
        <vers num="7.12" />
        <vers num="7.12.0" />
        <vers num="7.12.1" />
        <vers num="7.12.2" />
        <vers num="7.12.3" />
        <vers num="7.13" />
        <vers num="7.13.1" />
        <vers num="7.13.2" />
        <vers num="7.14" />
        <vers num="7.14.1" />
        <vers num="7.15" />
        <vers num="7.15.1" />
        <vers num="7.15.2" />
        <vers num="7.15.3" />
        <vers num="7.16.3" />
        <vers num="7.17.0" />
        <vers num="7.17.1" />
        <vers num="7.18.0" />
        <vers num="7.18.1" />
        <vers num="7.18.2" />
        <vers num="7.19.0" />
        <vers num="7.19.1" />
        <vers num="7.19.2" />
        <vers num="7.19.3" />
        <vers num="7.19.4" />
        <vers num="7.19.5" />
        <vers num="7.19.6" />
        <vers num="7.19.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-0735" reject="1" published="2010-03-18" name="CVE-2010-0735" modified="2010-03-18">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0969.  Reason: This candidate is a duplicate of CVE-2010-0969.  Notes: All CVE users should reference CVE-2010-0969 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0736" published="2010-03-19" name="CVE-2010-0736" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via "user-provided input."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/16/14" source="MLIST" patch="1">[oss-security] 20100316 Re: CVE Request: ViewVC 1.1.4 / 1.0.10 -- XSS via user-provided query form input</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/10/8" source="MLIST" patch="1">[oss-security] 20100310 CVE Request: ViewVC 1.1.4 / 1.0.10 -- XSS via user-provided query form input</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2326" source="CONFIRM" patch="1">http://viewvc.tigris.org/source/browse/viewvc?view=rev&amp;revision=2326</ref>
      <ref url="http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2313&amp;r2=2342&amp;pathrev=HEAD" source="CONFIRM">http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?r1=2313&amp;r2=2342&amp;pathrev=HEAD</ref>
    </refs>
    <vuln_soft>
      <prod vendor="viewvc" name="viewvc">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers prev="1" num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0738" published="2010-04-28" name="CVE-2010-0738" modified="2012-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0379.html" source="REDHAT">RHSA-2010:0379</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0378.html" source="REDHAT">RHSA-2010:0378</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0377.html" source="REDHAT">RHSA-2010:0377</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0376.html" source="REDHAT">RHSA-2010:0376</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=574105" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=574105</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58147" source="XF">jboss-jmxconsole-security-bypass(58147)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0992" source="VUPEN" adv="1">ADV-2010-0992</ref>
      <ref url="http://www.securityfocus.com/bid/39710" source="BID">39710</ref>
      <ref url="http://securitytracker.com/id?1023918" source="SECTRACK">1023918</ref>
      <ref url="http://securityreason.com/securityalert/8408" source="SREASON">8408</ref>
      <ref url="http://secunia.com/advisories/39563" source="SECUNIA" adv="1">39563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2" />
        <vers num="4.2.0" edition="cp01" />
        <vers num="4.2.0" edition="cp02" />
        <vers num="4.2.0" edition="cp03" />
        <vers num="4.2.0" edition="cp04" />
        <vers num="4.2.0" edition="cp05" />
        <vers num="4.2.0" edition="cp06" />
        <vers num="4.2.0" edition="cp07" />
        <vers num="4.2.0" edition="cp08" />
        <vers num="4.3" />
        <vers num="4.3.0" edition="cp01" />
        <vers num="4.3.0" edition="cp02" />
        <vers num="4.3.0" edition="cp03" />
        <vers num="4.3.0" edition="cp04" />
        <vers num="4.3.0" edition="cp05" />
        <vers num="4.3.0" edition="cp06" />
        <vers num="4.3.0" edition="cp07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0739" published="2010-04-16" name="CVE-2010-0739" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572941" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572941</ref>
      <ref url="http://www.ubuntu.com/usn/USN-937-1" source="UBUNTU">USN-937-1</ref>
      <ref url="http://www.securityfocus.com/bid/39500" source="BID">39500</ref>
      <ref url="http://secunia.com/advisories/39390" source="SECUNIA" adv="1">39390</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11468" source="OVAL">oval:org.mitre.oval:def:11468</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041573.html" source="FEDORA">FEDORA-2010-8273</ref>
      <ref url="http://git.frugalware.org/gitweb/gitweb.cgi?p=frugalware-stable.git;a=blob;f=source/xapps-extra/tetex/texlive-CVE-2010-0739-int-overflow.patch" source="CONFIRM">http://git.frugalware.org/gitweb/gitweb.cgi?p=frugalware-stable.git;a=blob;f=source/xapps-extra/tetex/texlive-CVE-2010-0739-int-overflow.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tug" name="tetex">
        <vers num="" />
      </prod>
      <prod vendor="tug" name="tex_live">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0740" published="2010-03-26" name="CVE-2010-0740" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.openssl.org/news/secadv_20100324.txt

'Affected versions depend on the C compiler used with OpenSSL:

- If 'short' is a 16-bit integer, this issue applies only to OpenSSL 0.9.8m.
- Otherwise, this issue applies to OpenSSL 0.9.8f through 0.9.8m.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0710" source="VUPEN" patch="1" adv="1">ADV-2010-0710</ref>
      <ref url="http://www.openssl.org/news/secadv_20100324.txt" source="CONFIRM" patch="1" adv="1">http://www.openssl.org/news/secadv_20100324.txt</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.2.1a has been released</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.0.6a has been released</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1216" source="VUPEN">ADV-2010-1216</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0933" source="VUPEN">ADV-2010-0933</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0839" source="VUPEN">ADV-2010-0839</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securitytracker.com/id?1023748" source="SECTRACK">1023748</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:076" source="MANDRIVA">MDVSA-2010:076</ref>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://secunia.com/advisories/43311" source="SECUNIA">43311</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/39932" source="SECUNIA">39932</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11731" source="OVAL">oval:org.mitre.oval:def:11731</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html" source="FEDORA">FEDORA-2010-5744</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers num="0.9.8k" />
        <vers num="0.9.8l" />
        <vers num="0.9.8m" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0741" published="2010-04-12" name="CVE-2010-0741" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0476.html" source="REDHAT">RHSA-2010:0476</ref>
      <ref url="https://patchwork.kernel.org/patch/56479/" source="CONFIRM">https://patchwork.kernel.org/patch/56479/</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=577218" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=577218</ref>
      <ref url="https://bugs.edge.launchpad.net/ubuntu/+source/qemu-kvm/+bug/458521" source="CONFIRM">https://bugs.edge.launchpad.net/ubuntu/+source/qemu-kvm/+bug/458521</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0760" source="VUPEN" adv="1">ADV-2010-0760</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0271.html" source="REDHAT">RHSA-2010:0271</ref>
      <ref url="http://securitytracker.com/id?1023798" source="SECTRACK">1023798</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11143" source="OVAL">oval:org.mitre.oval:def:11143</ref>
      <ref url="http://openwall.com/lists/oss-security/2010/03/29/4" source="MLIST">[oss-security] 20100329 CVE-2010-0741 qemu: Improper handling of erroneous data provided by Linux virtio-net driver</ref>
      <ref url="http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02495.html" source="MLIST">[qemu-devel] 20091029 [PATCH] whitelist host virtio networking features [was Re: qemu-kvm-0.11 regression, crashes on older ...]</ref>
      <ref url="http://lists.gnu.org/archive/html/qemu-devel/2009-10/msg02480.html" source="MLIST">[qemu-devel] 20091029 Re: qemu-kvm-0.11 regression, crashes on older guests with virtio network</ref>
      <ref url="http://git.kernel.org/?p=virt/kvm/qemu-kvm.git;a=commit;h=184bd0484533b725194fa517ddc271ffd74da7c9" source="CONFIRM">http://git.kernel.org/?p=virt/kvm/qemu-kvm.git;a=commit;h=184bd0484533b725194fa517ddc271ffd74da7c9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0742" published="2010-06-03" name="CVE-2010-0742" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1313" source="VUPEN" patch="1" adv="1">ADV-2010-1313</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.2.1a has been released</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.0.6a has been released</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=598738" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=598738</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3105" source="VUPEN">ADV-2010-3105</ref>
      <ref url="http://www.securityfocus.com/bid/40502" source="BID">40502</ref>
      <ref url="http://www.openssl.org/news/secadv_20100601.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20100601.txt</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/42457" source="SECUNIA">42457</ref>
      <ref url="http://secunia.com/advisories/40024" source="SECUNIA" adv="1">40024</ref>
      <ref url="http://secunia.com/advisories/40000" source="SECUNIA" adv="1">40000</ref>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=2211&amp;user=guest&amp;pass=guest" source="CONFIRM">http://rt.openssl.org/Ticket/Display.html?id=2211&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12395" source="OVAL">oval:org.mitre.oval:def:12395</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129138643405740&amp;w=2" source="HP">HPSBUX02610</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129138643405740&amp;w=2" source="HP">HPSBUX02610</ref>
      <ref url="http://cvs.openssl.org/filediff?f=openssl/crypto/cms/cms_asn1.c&amp;v1=1.8&amp;v2=1.8.6.1" source="CONFIRM">http://cvs.openssl.org/filediff?f=openssl/crypto/cms/cms_asn1.c&amp;v1=1.8&amp;v2=1.8.6.1</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=19693" source="CONFIRM">http://cvs.openssl.org/chngview?cn=19693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.3a" />
        <vers num="0.9.4" />
        <vers num="0.9.5" edition="beta1" />
        <vers num="0.9.5" edition="beta2" />
        <vers num="0.9.5a" edition="beta1" />
        <vers num="0.9.5a" edition="beta2" />
        <vers num="0.9.6" edition="beta1" />
        <vers num="0.9.6" edition="beta2" />
        <vers num="0.9.6" edition="beta3" />
        <vers num="0.9.6a" edition="beta1" />
        <vers num="0.9.6a" edition="beta2" />
        <vers num="0.9.6a" edition="beta3" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7" edition="beta4" />
        <vers num="0.9.7" edition="beta5" />
        <vers num="0.9.7" edition="beta6" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
        <vers num="0.9.7e" />
        <vers num="0.9.7f" />
        <vers num="0.9.7g" />
        <vers num="0.9.7h" />
        <vers num="0.9.7i" />
        <vers num="0.9.7j" />
        <vers num="0.9.7k" />
        <vers num="0.9.7l" />
        <vers num="0.9.7m" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers num="0.9.8k" />
        <vers num="0.9.8l" />
        <vers num="0.9.8m" />
        <vers prev="1" num="0.9.8n" />
        <vers num="1.0.0" edition="beta1" />
        <vers num="1.0.0" edition="beta2" />
        <vers num="1.0.0" edition="beta3" />
        <vers num="1.0.0" edition="beta4" />
        <vers num="1.0.0" edition="beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0743" published="2010-04-08" name="CVE-2010-0743" modified="2010-09-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in isns.c in (1) Linux SCSI target framework (aka tgt or scsi-target-utils) 1.0.3, 0.9.5, and earlier and (2) iSCSI Enterprise Target (aka iscsitarget) 0.4.16 allow remote attackers to cause a denial of service (tgtd daemon crash) or possibly have unspecified other impact via vectors that involve the isns_attr_query and qry_rsp_handle functions, and are related to (a) client appearance and (b) client disappearance messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/tomo/tgt.git;a=commit;h=107d922706cd36f3bb79bcca9bc4678c32f22e59" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/tomo/tgt.git;a=commit;h=107d922706cd36f3bb79bcca9bc4678c32f22e59</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574935" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=574935</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=576359" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=576359</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57496" source="XF">lstf-isns-format-string(57496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1786" source="VUPEN">ADV-2010-1786</ref>
      <ref url="http://www.securityfocus.com/bid/39127" source="BID">39127</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:131" source="MANDRIVA">MDVSA-2010:131</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2042" source="DEBIAN">DSA-2042</ref>
      <ref url="http://secunia.com/advisories/39726" source="SECUNIA">39726</ref>
      <ref url="http://secunia.com/advisories/39142" source="SECUNIA" adv="1">39142</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11248" source="OVAL">oval:org.mitre.oval:def:11248</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127005132403189&amp;w=2" source="MLIST">[oss-security] 20100331 iscsitarget/scsi-target-tuils format string CVE assignment</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="iscsitarget" name="iscsitarget">
        <vers num="0.4.16" />
      </prod>
      <prod vendor="zaal" name="tgt">
        <vers prev="1" num="0.9.5" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0744" published="2010-04-20" name="CVE-2010-0744" modified="2010-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1109" source="VUPEN">ADV-2010-1109</ref>
      <ref url="http://www.securityfocus.com/bid/35507" source="BID">35507</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/01/4" source="MLIST">[oss-security] 20100401 Re: CVE Request -- aMSN -- improper SSL certificate validation (MITM)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/10/4" source="MLIST">[oss-security] 20100310 CVE Request -- aMSN -- improper SSL certificate validation (MITM)</ref>
      <ref url="http://www.opensource-archive.org/showthread.php?p=183821" source="CONFIRM">http://www.opensource-archive.org/showthread.php?p=183821</ref>
      <ref url="http://secunia.com/advisories/39796" source="SECUNIA">39796</ref>
      <ref url="http://secunia.com/advisories/35621" source="SECUNIA" adv="1">35621</ref>
      <ref url="http://seclists.org/bugtraq/2009/Jun/239" source="BUGTRAQ">20090626 aMSN SSL Certificate Vulnerability</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041079.html" source="FEDORA">FEDORA-2010-7378</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041046.html" source="FEDORA">FEDORA-2010-7373</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572818" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=572818</ref>
      <ref url="http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/soap.tcl?r1=11891&amp;r2=11991&amp;pathrev=11991" source="CONFIRM" adv="1">http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/soap.tcl?r1=11891&amp;r2=11991&amp;pathrev=11991</ref>
      <ref url="http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/sip.tcl?r1=11953&amp;r2=11991&amp;pathrev=11991" source="CONFIRM" adv="1">http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/sip.tcl?r1=11953&amp;r2=11991&amp;pathrev=11991</ref>
      <ref url="http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/proxy.tcl?r1=11886&amp;r2=11991&amp;pathrev=11991" source="CONFIRM" adv="1">http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/amsn/proxy.tcl?r1=11886&amp;r2=11991&amp;pathrev=11991</ref>
      <ref url="http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/?view=log&amp;pathrev=11991" source="CONFIRM" adv="1">http://amsn.svn.sourceforge.net/viewvc/amsn/trunk/?view=log&amp;pathrev=11991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alvaro" name="alvaros_messenger">
        <vers num="0.83" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers prev="1" num="0.98.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0745" published="2010-05-20" name="CVE-2010-0745" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://dovecot.org/list/dovecot-news/2010-March/000152.html" source="MLIST" patch="1" adv="1">[dovecot-news] 20100308 v1.2.11 released</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572268" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572268</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1226" source="VUPEN">ADV-2010-1226</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN" adv="1">ADV-2010-1107</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/10/6" source="MLIST">[oss-security] 20100310 CVE Request -- Dovecot v1.2.11 -- DoS (excessive CPU use) by processing email with huge header</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:104" source="MANDRIVA">MDVSA-2010:104</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-0745" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-0745</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127013715227551&amp;w=2" source="MLIST">[oss-security] 20100401 Re: CVE Request -- Dovecot v1.2.11 -- DoS (excessive CPU use) by processing email with huge header</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://dovecot.org/pipermail/dovecot/2010-February/047190.html" source="MLIST">[dovecot] 20100227 Possible CPU Denial-Of-Service attack to dovecot IMAP.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dovecot" name="dovecot">
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0750" published="2010-04-06" name="CVE-2010-0750" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://cgit.freedesktop.org/PolicyKit/commit/?id=14bdfd816512a82b1ad258fa143ae5faa945df8a" source="CONFIRM" patch="1">http://cgit.freedesktop.org/PolicyKit/commit/?id=14bdfd816512a82b1ad258fa143ae5faa945df8a</ref>
      <ref url="http://bugs.freedesktop.org/show_bug.cgi?id=26982" source="CONFIRM" patch="1">http://bugs.freedesktop.org/show_bug.cgi?id=26982</ref>
      <ref url="https://launchpad.net/bugs/532852" source="CONFIRM">https://launchpad.net/bugs/532852</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57543" source="XF">policykit-pkexec-info-disc(57543)</ref>
      <ref url="http://secunia.com/advisories/39149" source="SECUNIA" adv="1">39149</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127014999113790&amp;w=2" source="MLIST">[oss-security] 20100401 Re: CVE Request: policykit (minor)</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127014095301235&amp;w=2" source="MLIST">[oss-security] 20100401 CVE Request: policykit (minor)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="policykit">
        <vers num="0.96" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0751" published="2010-04-06" name="CVE-2010-0751" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ip_evictor function in ip_fragment.c in libnids 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0791" source="VUPEN" patch="1" adv="1">ADV-2010-0791</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0777" source="VUPEN" patch="1" adv="1">ADV-2010-0777</ref>
      <ref url="http://xorl.wordpress.com/2010/04/04/libnids-ip-fragmentation-remote-null-pointer-dereference/" source="MISC">http://xorl.wordpress.com/2010/04/04/libnids-ip-fragmentation-remote-null-pointer-dereference/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57428" source="XF">libnids-ipfragment-dos(57428)</ref>
      <ref url="http://www.securityfocus.com/bid/39142" source="BID">39142</ref>
      <ref url="http://secunia.com/advisories/39249" source="SECUNIA" adv="1">39249</ref>
      <ref url="http://secunia.com/advisories/39225" source="SECUNIA" adv="1">39225</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038410.html" source="FEDORA">FEDORA-2010-5562</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038388.html" source="FEDORA">FEDORA-2010-5545</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038375.html" source="FEDORA">FEDORA-2010-5535</ref>
      <ref url="http://freefr.dl.sourceforge.net/project/libnids/libnids/1.24/libnids-1.24.releasenotes.txt" source="CONFIRM">http://freefr.dl.sourceforge.net/project/libnids/libnids/1.24/libnids-1.24.releasenotes.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rafal_wojtczuk" name="libnids">
        <vers num="1.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0752" published="2010-02-26" name="CVE-2010-0752" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/724286" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/724286</ref>
      <ref url="http://drupal.org/node/723776" source="CONFIRM" patch="1">http://drupal.org/node/723776</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56504" source="XF">weeklyarchive-nodetype-info-disclosure(56504)</ref>
      <ref url="http://www.securityfocus.com/bid/38397" source="BID">38397</ref>
      <ref url="http://secunia.com/advisories/38717" source="SECUNIA" adv="1">38717</ref>
      <ref url="http://osvdb.org/62565" source="OSVDB">62565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="earl_dunovant" name="week">
        <vers num="6.x-1.0" />
        <vers num="6.x-1.x-dev" />
        <vers num="6.x-2.0" />
        <vers num="6.x-2.1" />
        <vers num="6.x-2.2" />
        <vers num="6.x-2.3" />
        <vers num="6.x-2.4" />
        <vers num="6.x-2.5" />
        <vers num="6.x-2.6" />
        <vers num="6.x-2.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0753" published="2010-02-26" name="CVE-2010-0753" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter to ajax/print.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56541" source="XF">sql-reports-print-sql-injection(56541)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56476" source="XF">sqlreport-userid-sql-injection(56476)</ref>
      <ref url="http://www.securityfocus.com/bid/38361" source="BID">38361</ref>
      <ref url="http://www.packetstormsecurity.com/1002-exploits/joomlasqlreport-sql.txt" source="MISC">http://www.packetstormsecurity.com/1002-exploits/joomlasqlreport-sql.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/11549" source="EXPLOIT-DB">11549</ref>
      <ref url="http://secunia.com/advisories/38678" source="SECUNIA" adv="1">38678</ref>
      <ref url="http://osvdb.org/62534" source="OSVDB">62534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="componentslab" name="com_sqlreport">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0754" published="2010-02-26" name="CVE-2010-0754" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitrary web script or HTML via the which parameter in a copy action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56518" source="XF">wikyblog-which-xss(56518)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0468" source="VUPEN" adv="1">ADV-2010-0468</ref>
      <ref url="http://www.securityfocus.com/bid/38386" source="BID">38386</ref>
      <ref url="http://www.exploit-db.com/exploits/11560" source="EXPLOIT-DB">11560</ref>
      <ref url="http://secunia.com/advisories/38699" source="SECUNIA" adv="1">38699</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt</ref>
      <ref url="http://osvdb.org/62558" source="OSVDB">62558</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wikyblog" name="wikyblog">
        <vers num="1.7.2" />
        <vers num="1.7.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0755" published="2010-02-26" name="CVE-2010-0755" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in the langFile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56519" source="XF">wikyblog-langfile-file-include(56519)</ref>
      <ref url="http://www.securityfocus.com/bid/38386" source="BID">38386</ref>
      <ref url="http://www.exploit-db.com/exploits/11560" source="EXPLOIT-DB">11560</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt</ref>
      <ref url="http://osvdb.org/62647" source="OSVDB">62647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wikyblog" name="wikyblog">
        <vers num="1.7.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0756" published="2010-02-26" name="CVE-2010-0756" modified="2010-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56594" source="XF">wikyblog-multiple-session-hijacking(56594)</ref>
      <ref url="http://www.securityfocus.com/bid/38386" source="BID">38386</ref>
      <ref url="http://www.exploit-db.com/exploits/11560" source="EXPLOIT-DB">11560</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wikyblog" name="wikyblog">
        <vers num="1.7.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0757" published="2010-02-26" name="CVE-2010-0757" modified="2010-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html

CWE-434: Unrestricted Upload of File with Dangerous Type</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56517" source="XF">wikyblog-index-file-upload(56517)</ref>
      <ref url="http://www.securityfocus.com/bid/38386" source="BID">38386</ref>
      <ref url="http://www.exploit-db.com/exploits/11560" source="EXPLOIT-DB">11560</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/wikyblog-rfishellxss.txt</ref>
      <ref url="http://osvdb.org/62648" source="OSVDB">62648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wikyblog" name="wikyblog">
        <vers num="1.7.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0758" published="2010-02-26" name="CVE-2010-0758" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news_desc.php in Softbiz Jobs allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56453" source="XF">jobboard-newsdesc-sql-injection(56453)</ref>
      <ref url="http://www.securityfocus.com/bid/38344" source="BID">38344</ref>
      <ref url="http://www.exploit-db.com/exploits/11518" source="EXPLOIT-DB">11518</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/softbizjobs-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/softbizjobs-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="softbizscripts" name="softbiz_jobs_and_recruitment_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0759" published="2010-02-26" name="CVE-2010-0759" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allows remote attackers to read, and possibly include and execute, arbitrary files via directory traversal sequences in the files[] parameter, a different vector than CVE-2010-0760.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56380" source="XF">scriptegrator-jsloader-file-include(56380)</ref>
      <ref url="http://www.securityfocus.com/bid/38296" source="BID">38296</ref>
      <ref url="http://www.osvdb.org/62486" source="OSVDB">62486</ref>
      <ref url="http://www.exploit-db.com/exploits/11498" source="EXPLOIT-DB">11498</ref>
      <ref url="http://secunia.com/advisories/38637" source="SECUNIA" adv="1">38637</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/joomlascriptegrator-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/joomlascriptegrator-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greatjoomla" name="scriptegrator_plugin">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0760" published="2010-02-26" name="CVE-2010-0760" modified="2010-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in the Core Design Scriptegrator plugin 1.4.1 for Joomla! allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) file parameter to libraries/jquery/js/ui/jsloader.php and the (2) files[] parameter to libraries/jquery/js/jsloader.php, a different vector than CVE-2010-0759.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/62485" source="OSVDB">62485</ref>
      <ref url="http://www.osvdb.org/62484" source="OSVDB">62484</ref>
      <ref url="http://secunia.com/advisories/38637" source="SECUNIA" adv="1">38637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="greatjoomla" name="scriptegrator_plugin">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0761" published="2010-03-02" name="CVE-2010-0761" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56210" source="XF">booksebooks-index-sql-injection(56210)</ref>
      <ref url="http://www.securityfocus.com/bid/38189" source="BID">38189</ref>
      <ref url="http://www.indonesiancoder.org/booksebooks-rental-software-sql-injection-vulnerability" source="MISC">http://www.indonesiancoder.org/booksebooks-rental-software-sql-injection-vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/11402" source="EXPLOIT-DB">11402</ref>
      <ref url="http://secunia.com/advisories/38520" source="SECUNIA" adv="1">38520</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/ebooksrental-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/ebooksrental-sql.txt</ref>
      <ref url="http://osvdb.org/62277" source="OSVDB">62277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodityrentals" name="books/ebooks_rentals_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0762" published="2010-03-02" name="CVE-2010-0762" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56209" source="XF">cdrentals-index-sql-injection(56209)</ref>
      <ref url="http://www.securityfocus.com/bid/38184" source="BID">38184</ref>
      <ref url="http://www.osvdb.org/62278" source="OSVDB">62278</ref>
      <ref url="http://www.indonesiancoder.org/cd-rentals-script-sql-injection-vulnerability" source="MISC">http://www.indonesiancoder.org/cd-rentals-script-sql-injection-vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/11401" source="EXPLOIT-DB">11401</ref>
      <ref url="http://secunia.com/advisories/38519" source="SECUNIA" adv="1">38519</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/cdrentals-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/cdrentals-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodityrentals" name="cd_rental_software">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0763" published="2010-03-02" name="CVE-2010-0763" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38208" source="BID">38208</ref>
      <ref url="http://www.exploit-db.com/exploits/11410" source="EXPLOIT-DB">11410</ref>
      <ref url="http://secunia.com/advisories/38552" source="SECUNIA" adv="1">38552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="commodityrentals" name="vacation_rental_software">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0764" published="2010-03-02" name="CVE-2010-0764" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in KuwaitPHP eSmile allows remote attackers to execute arbitrary SQL commands via the cid parameter in a show action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56206" source="XF">esmile-index-sql-injection(56206)</ref>
      <ref url="http://www.exploit-db.com/exploits/11382" source="EXPLOIT-DB">11382</ref>
      <ref url="http://secunia.com/advisories/38548" source="SECUNIA" adv="1">38548</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/esmile-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/esmile-sql.txt</ref>
      <ref url="http://osvdb.org/62272" source="OSVDB">62272</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kuwaitphp" name="esmile">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0765" published="2010-03-02" name="CVE-2010-0765" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _database/forumFips.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56183" source="XF">fipsforum-forumfips-information-disclosure(56183)</ref>
      <ref url="http://www.exploit-db.com/exploits/11361" source="EXPLOIT-DB">11361</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/fipsforum-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/fipsforum-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fipsasp" name="fipsforum">
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0766" published="2010-03-03" name="CVE-2010-0766" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Swap4 function in valet4.dll in Luxology Modo 401 allows user-assisted remote attackers to execute arbitrary code via a .LXO file containing a CHNL subchunk associated with an invalid length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38460" source="BID">38460</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509843/100/0/threaded" source="BUGTRAQ">20100303 CORRECTION: CORE-2009-0913 - Luxology Modo 401 .LXO Integer Overflow</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509810/100/0/threaded" source="BUGTRAQ">20100302 Luxology Modo 401 .LXO Integer Overflow</ref>
      <ref url="http://www.coresecurity.com/content/luxology-modo-lxo-vulnerability" source="MISC">http://www.coresecurity.com/content/luxology-modo-lxo-vulnerability</ref>
      <ref url="http://secunia.com/advisories/38784" source="SECUNIA">38784</ref>
      <ref url="http://osvdb.org/62669" source="OSVDB">62669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="luxology" name="modo">
        <vers num="401" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0768" published="2010-04-01" name="CVE-2010-0768" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57164" source="XF">was-admin-console-xss(57164)</ref>
      <ref url="http://www.securityfocus.com/bid/39051" source="BID">39051</ref>
      <ref url="http://secunia.com/advisories/39140" source="SECUNIA" adv="1">39140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers prev="1" num="6.0.2.39" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers prev="1" num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0769" published="2010-04-01" name="CVE-2010-0769" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57185" source="XF">was-wsadmin-info-disclosure(57185)</ref>
      <ref url="http://secunia.com/advisories/39140" source="SECUNIA" adv="1">39140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers prev="1" num="6.0.2.39" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers prev="1" num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0770" published="2010-04-01" name="CVE-2010-0770" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK93653" source="AIXAPAR" patch="1" adv="1">PK93653</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57182" source="XF">was-orb-client-dos(57182)</ref>
      <ref url="http://www.securityfocus.com/bid/39056" source="BID">39056</ref>
      <ref url="http://secunia.com/advisories/39140" source="SECUNIA" adv="1">39140</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers prev="1" num="6.0.2.39" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers prev="1" num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0772" published="2010-04-27" name="CVE-2010-0772" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58039" source="XF">websphere-mq-ccd-dos(58039)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1083" source="VUPEN">ADV-2010-1083</ref>
      <ref url="http://securitytracker.com/id?1023961" source="SECTRACK">1023961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0774" published="2010-05-17" name="CVE-2010-0774" modified="2010-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58554" source="XF">was-pkipath-security-bypass(58554)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK96427" source="AIXAPAR">PK96427</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0775" published="2010-05-17" name="CVE-2010-0775" modified="2010-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a crafted request, related to the nodeagent and Deployment Manager components.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58555" source="XF">was-dmgr-nodeagent-dos(58555)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0776" published="2010-05-17" name="CVE-2010-0776" modified="2010-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58556" source="XF">was-webcontainer-dos(58556)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0777" published="2010-05-17" name="CVE-2010-0777" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58557" source="XF">was-webcontainer-info-disclosure(58557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1200" source="VUPEN">ADV-2010-1200</ref>
      <ref url="http://www.securityfocus.com/bid/40277" source="BID">40277</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://secunia.com/advisories/39838" source="SECUNIA">39838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0778" published="2010-06-24" name="CVE-2010-0778" modified="2010-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59646" source="XF">was-admincons-xss(59646)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.31" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0779" published="2010-06-24" name="CVE-2010-0779" modified="2010-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.33, and 7.0 before 7.0.0.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59647" source="XF">was-admin-xss(59647)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.2" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.41" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.31" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0780" published="2011-10-29" name="CVE-2010-0780" modified="2011-10-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM WebSphere MQ 7.x before 7.0.1.4 allows remote attackers to cause a denial of service (disk consumption) via multiple connection attempts to a stopped queue manager.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/60638" source="XF">wmq-diskspace-dos(60638)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg1IZ75124" source="AIXAPAR">IZ75124</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014224" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.1.0" />
        <vers num="7.0.1.1" />
        <vers num="7.0.1.2" />
        <vers num="7.0.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0781" published="2010-09-21" name="CVE-2010-0781" modified="2010-11-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61890" source="XF">was-adminconsole-dos(61890)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://secunia.com/advisories/41722" source="SECUNIA">41722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.31" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0782" published="2010-10-20" name="CVE-2010-0782" modified="2010-10-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/60018" source="XF">websphere-mq-subjectdn-spoofing(60018)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014224" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014224</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707" source="AIXAPAR">IZ68707</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="6.0" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.2.0" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.1.0" />
        <vers num="7.0.1.1" />
        <vers num="7.0.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0783" published="2010-11-09" name="CVE-2010-0783" modified="2010-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62947" source="XF">was-admin-cons-xss(62947)</ref>
      <ref url="http://www.osvdb.org/69007" source="OSVDB">69007</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27004980" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27004980</ref>
      <ref url="http://securitytracker.com/id?1024686" source="SECTRACK">1024686</ref>
      <ref url="http://secunia.com/advisories/42136" source="SECUNIA" adv="1">42136</ref>
      <ref url="http://secunia.com/advisories/41722" source="SECUNIA" adv="1">41722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.24" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.26" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.31" />
        <vers num="6.1.0.32" />
        <vers num="6.1.0.33" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.10" />
        <vers num="7.0.0.11" />
        <vers num="7.0.0.12" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.6" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0784" published="2010-11-09" name="CVE-2010-0784" modified="2010-11-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62948" source="XF">was-admins-console-xss(62948)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2595" source="VUPEN" adv="1">ADV-2010-2595</ref>
      <ref url="http://www.securityfocus.com/bid/43874" source="BID">43874</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27004980" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27004980</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM23872" source="AIXAPAR">PM23872</ref>
      <ref url="http://secunia.com/advisories/41722" source="SECUNIA" adv="1">41722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.10" />
        <vers num="7.0.0.11" />
        <vers num="7.0.0.12" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.6" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0785" published="2010-11-09" name="CVE-2010-0785" modified="2010-11-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62949" source="XF">was-admin-console-csrf(62949)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2595" source="VUPEN" adv="1">ADV-2010-2595</ref>
      <ref url="http://www.securityfocus.com/bid/43875" source="BID">43875</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27004980" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27004980</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM23874" source="AIXAPAR">PM23874</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM18909" source="AIXAPAR">PM18909</ref>
      <ref url="http://secunia.com/advisories/41722" source="SECUNIA" adv="1">41722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.31" />
        <vers num="6.1.0.33" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.11" />
        <vers num="7.0.0.13" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.6" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0786" published="2010-11-09" name="CVE-2010-0786" modified="2010-11-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62950" source="XF">was-jaxws-dos(62950)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.10" />
        <vers num="7.0.0.11" />
        <vers num="7.0.0.12" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.6" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0787" published="2010-03-02" name="CVE-2010-0787" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=6853" source="CONFIRM" patch="1">https://bugzilla.samba.org/show_bug.cgi?id=6853</ref>
      <ref url="http://www.securityfocus.com/bid/37992" source="BID" patch="1">37992</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=558833" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=558833</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=532940" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=532940</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55944" source="XF">sambaclient-mountcifs-symlink(55944)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1062" source="VUPEN">ADV-2010-1062</ref>
      <ref url="http://www.ubuntu.com/usn/USN-893-1" source="UBUNTU">USN-893-1</ref>
      <ref url="http://www.securityfocus.com/bid/39898" source="BID">39898</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:090" source="MANDRIVA">MDVSA-2010:090</ref>
      <ref url="http://secunia.com/advisories/38357" source="SECUNIA" adv="1">38357</ref>
      <ref url="http://secunia.com/advisories/38308" source="SECUNIA" adv="1">38308</ref>
      <ref url="http://secunia.com/advisories/38286" source="SECUNIA" adv="1">38286</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034470.html" source="FEDORA">FEDORA-2010-1218</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034444.html" source="FEDORA">FEDORA-2010-1190</ref>
      <ref url="http://git.samba.org/?p=samba.git;a=commit;h=a0c31ec1c8d1220a5884e40d9ba6b191a04a24d5" source="CONFIRM">http://git.samba.org/?p=samba.git;a=commit;h=a0c31ec1c8d1220a5884e40d9ba6b191a04a24d5</ref>
      <ref url="http://git.samba.org/?p=samba.git;a=commit;h=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80" source="CONFIRM">http://git.samba.org/?p=samba.git;a=commit;h=3ae5dac462c4ed0fb2cd94553583c56fce2f9d80</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0.22" />
        <vers num="3.0.28a" />
        <vers num="3.2.3" />
        <vers num="3.4.0" />
        <vers num="3.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0788" published="2010-03-02" name="CVE-2010-0788" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=558833" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=558833</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=532940" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=532940</ref>
      <ref url="http://www.securityfocus.com/bid/38563" source="BID">38563</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509894/100/0/threaded" source="BUGTRAQ">20100305 Re: ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509893/100/0/threaded" source="BUGTRAQ">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/38371" source="SECUNIA" adv="1">38371</ref>
      <ref url="http://secunia.com/advisories/38327" source="SECUNIA" adv="1">38327</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Mar/122" source="FULLDISC">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034422.html" source="FEDORA">FEDORA-2010-1168</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-January/034403.html" source="FEDORA">FEDORA-2010-1145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0789" published="2010-03-02" name="CVE-2010-0789" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=532940" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=532940</ref>
      <ref url="http://www.securityfocus.com/bid/37983" source="BID" patch="1">37983</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1989" source="DEBIAN" patch="1">DSA-1989</ref>
      <ref url="http://sourceforge.net/projects/fuse/files/fuse-2.X/2.7.5/fuse-2.7.5.tar.gz/download" source="CONFIRM" patch="1">http://sourceforge.net/projects/fuse/files/fuse-2.X/2.7.5/fuse-2.7.5.tar.gz/download</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=558833" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=558833</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55945" source="XF">fuse-fusermount-dos(55945)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.ubuntu.com/usn/USN-892-1" source="UBUNTU">USN-892-1</ref>
      <ref url="http://sourceforge.net/projects/fuse/files/ReleaseNotes/fuse-2.8.3.html/view" source="CONFIRM">http://sourceforge.net/projects/fuse/files/ReleaseNotes/fuse-2.8.3.html/view</ref>
      <ref url="http://secunia.com/advisories/38437" source="SECUNIA" adv="1">38437</ref>
      <ref url="http://secunia.com/advisories/38359" source="SECUNIA" adv="1">38359</ref>
      <ref url="http://secunia.com/advisories/38287" source="SECUNIA" adv="1">38287</ref>
      <ref url="http://secunia.com/advisories/38261" source="SECUNIA" adv="1">38261</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html" source="SUSE">SUSE-SR:2010:003</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034580.html" source="FEDORA">FEDORA-2010-1159</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/034518.html" source="FEDORA">FEDORA-2010-1140</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567633" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=567633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fuse" name="fuse">
        <vers num="1.9" />
        <vers num="2.0" edition="pre0" />
        <vers num="2.0" edition="pre1" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" edition="pre" />
        <vers num="2.3" edition="rc1" />
        <vers num="2.3.0" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.3" />
        <vers num="2.6.5" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0790" published="2010-03-10" name="CVE-2010-0790" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine the existence of arbitrary files via the mountpoint name.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2010/Mar/122" source="FULLDISC" patch="1">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38563" source="BID">38563</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509894/100/0/threaded" source="BUGTRAQ">20100305 Re: ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509893/100/0/threaded" source="BUGTRAQ">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0791" published="2010-03-10" name="CVE-2010-0791" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2010/Mar/122" source="FULLDISC" patch="1">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/38563" source="BID">38563</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509894/100/0/threaded" source="BUGTRAQ">20100305 Re: ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509893/100/0/threaded" source="BUGTRAQ">20100305 ncpfs, Multiple Vulnerabilities</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncpfs" name="ncpfs">
        <vers num="2.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0792" published="2010-03-05" name="CVE-2010-0792" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38531" source="BID" patch="1">38531</ref>
      <ref url="http://fcron.free.fr/" source="CONFIRM" patch="1">http://fcron.free.fr/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56680" source="XF">fcron-fcrontab-symlink(56680)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0730" source="VUPEN">ADV-2010-0730</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509873/100/0/threaded" source="BUGTRAQ">20100304 fcrontab Information Disclosure Vulnerability</ref>
      <ref url="http://www.osvdb.org/62718" source="OSVDB">62718</ref>
      <ref url="http://securitytracker.com/id?1023677" source="SECTRACK">1023677</ref>
      <ref url="http://secunia.com/advisories/39195" source="SECUNIA">39195</ref>
      <ref url="http://secunia.com/advisories/38796" source="SECUNIA" adv="1">38796</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Mar/97" source="FULLDISC">20100303 fcrontab Information Disclosure Vulnerability</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/038150.html" source="FEDORA">FEDORA-2010-4063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thibault_godouet" name="fcron">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2.1" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.9.0" />
        <vers num="2.9.1" />
        <vers num="2.9.2" />
        <vers num="2.9.3" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
        <vers num="2.9.5.1" />
        <vers num="2.9.6" />
        <vers num="2.9.7" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" edition="rc1" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0793" published="2010-03-16" name="CVE-2010-0793" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BarnOwl before 1.5.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted CC: header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://barnowl.mit.edu/wiki/barnowl-1.5.1-announce" source="CONFIRM" patch="1" adv="1">http://barnowl.mit.edu/wiki/barnowl-1.5.1-announce</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1218" source="VUPEN">ADV-2010-1218</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2049" source="DEBIAN">DSA-2049</ref>
      <ref url="http://secunia.com/advisories/39908" source="SECUNIA">39908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barnowl" name="barnowl">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.2.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.4.1" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.4" edition="rc1" />
        <vers prev="1" num="1.5" edition="rc1" />
        <vers prev="1" num="1.5" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0795" published="2010-03-02" name="CVE-2010-0795" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an event action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56008" source="XF">jeeventcalendars-index-sql-injection(56008)</ref>
      <ref url="http://www.securityfocus.com/bid/38012" source="BID">38012</ref>
      <ref url="http://www.exploit-db.com/exploits/11292" source="EXPLOIT-DB">11292</ref>
      <ref url="http://secunia.com/advisories/38408" source="SECUNIA" adv="1">38408</ref>
      <ref url="http://osvdb.org/62038" source="OSVDB">62038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="harmistechnology" name="com_jeeventcalendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0796" published="2010-03-02" name="CVE-2010-0796" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the eid parameter in a question action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56009" source="XF">jequiz-index-sql-injection(56009)</ref>
      <ref url="http://www.securityfocus.com/bid/38032" source="BID">38032</ref>
      <ref url="http://www.exploit-db.com/exploits/11287" source="EXPLOIT-DB">11287</ref>
      <ref url="http://secunia.com/advisories/38412" source="SECUNIA" adv="1">38412</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajequiz-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajequiz-sql.txt</ref>
      <ref url="http://osvdb.org/62039" source="OSVDB">62039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="harmistechnology" name="com_jeeventcalendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0797" published="2010-03-02" name="CVE-2010-0797" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-002/" source="CONFIRM" patch="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-002/</ref>
      <ref url="http://typo3.org/extensions/repository/view/t3blog/0.8.0/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/t3blog/0.8.0/</ref>
      <ref url="http://www.securityfocus.com/bid/38030" source="BID">38030</ref>
      <ref url="http://secunia.com/advisories/38388" source="SECUNIA" adv="1">38388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowflake" name="t3blog">
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers prev="1" num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0798" published="2010-03-02" name="CVE-2010-0798" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-002/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-002/</ref>
      <ref url="http://typo3.org/extensions/repository/view/t3blog/0.8.0/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/t3blog/0.8.0/</ref>
      <ref url="http://www.securityfocus.com/bid/38030" source="BID">38030</ref>
      <ref url="http://secunia.com/advisories/38388" source="SECUNIA" adv="1">38388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snowflake" name="t3blog">
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers prev="1" num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0799" published="2010-03-02" name="CVE-2010-0799" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11290" source="EXPLOIT-DB">11290</ref>
      <ref url="http://secunia.com/advisories/38409" source="SECUNIA" adv="1">38409</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpunity-lfi.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpunity-lfi.txt</ref>
      <ref url="http://osvdb.org/62036" source="OSVDB">62036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perlunity" name="phpunity.newsmanager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0800" published="2010-03-02" name="CVE-2010-0800" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a view_category action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56006" source="XF">documentseller-categoryid-sql-injection(56006)</ref>
      <ref url="http://www.securityfocus.com/bid/38024" source="BID">38024</ref>
      <ref url="http://www.securityfocus.com/bid/38017" source="BID">38017</ref>
      <ref url="http://www.exploit-db.com/exploits/11289" source="EXPLOIT-DB">11289</ref>
      <ref url="http://secunia.com/advisories/38410" source="SECUNIA" adv="1">38410</ref>
      <ref url="http://osvdb.org/62040" source="OSVDB">62040</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomservices" name="com_dms">
        <vers num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0801" published="2010-03-02" name="CVE-2010-0801" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authenticated users, with "Public Back-end" group permissions, to read arbitrary files via directory traversal sequences in the controller parameter in an edit task to administrator/index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38034" source="BID">38034</ref>
      <ref url="http://secunia.com/advisories/38434" source="SECUNIA" adv="1">38434</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlaautartitarot-traversal.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlaautartitarot-traversal.txt</ref>
      <ref url="http://osvdb.org/62041" source="OSVDB">62041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autartica" name="com_autartitarot">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0802" published="2010-03-02" name="CVE-2010-0802" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11297" source="EXPLOIT-DB">11297</ref>
      <ref url="http://secunia.com/advisories/38407" source="SECUNIA" adv="1">38407</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/ipbawards-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/ipbawards-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aleinbeen" name="(nv2)_awards">
        <vers num="1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0803" published="2010-03-02" name="CVE-2010-0803" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attackers to execute arbitrary SQL commands via the v parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55957" source="XF">jvideo-v-sql-injection(55957)</ref>
      <ref url="http://www.securityfocus.com/bid/37990" source="BID">37990</ref>
      <ref url="http://www.exploit-db.com/exploits/11280" source="EXPLOIT-DB">11280</ref>
      <ref url="http://secunia.com/advisories/38436" source="SECUNIA" adv="1">38436</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajvideodirect-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajvideodirect-sql.txt</ref>
      <ref url="http://osvdb.org/62042" source="OSVDB">62042</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jvideodirect" name="com_jvideodirect">
        <vers num="1.1" edition="rc3b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0804" published="2010-03-02" name="CVE-2010-0804" modified="2010-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in iBoutique 4.0 allows remote attackers to inject arbitrary web script or HTML via the key parameter in a products action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509126/100/0/threaded" source="BUGTRAQ">20100122 iBoutique v4.0</ref>
      <ref url="http://secunia.com/advisories/31871" source="SECUNIA" adv="1">31871</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/iboutique-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/iboutique-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netartmedia" name="iboutique">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0805" published="2010-03-31" name="CVE-2010-0805" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 7 and Internet Explorer 8 are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39025" source="BID" patch="1">39025</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-034" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510507/100/0/threaded" source="BUGTRAQ">20100402 ZDI-10-034: Microsoft Internet Explorer Tabular Data Control ActiveX Remote Code Execution Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8080" source="OVAL">oval:org.mitre.oval:def:8080</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0806" published="2010-03-10" name="CVE-2010-0806" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."</descript>
      <descript source="nvd">Further information on this vulnerability can be found at the following link from Microsoft:

http://support.microsoft.com/kb/981374</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/744549" source="CERT-VN" patch="1">VU#744549</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/981374.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/981374.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56772" source="XF">ms-ie-useafterfree-code-execution(56772)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0567" source="VUPEN" adv="1">ADV-2010-0567</ref>
      <ref url="http://www.securityfocus.com/bid/38615" source="BID">38615</ref>
      <ref url="http://secunia.com/advisories/38860" source="SECUNIA" adv="1">38860</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8446" source="OVAL">oval:org.mitre.oval:def:8446</ref>
      <ref url="http://osvdb.org/62810" source="OSVDB">62810</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0807" published="2010-03-31" name="CVE-2010-0807" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx

'Internet Explorer 5.01 Service Pack 4, Internet Explorer 6, Internet Explorer 6 Service Pack 1, and Internet Explorer 8 are not affected by this vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-089A.html" source="CERT">TA10-089A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-068A.html" source="CERT">TA10-068A</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0744" source="VUPEN" patch="1" adv="1">ADV-2010-0744</ref>
      <ref url="http://www.securityfocus.com/bid/39024" source="BID" patch="1">39024</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-018.mspx" source="MS" patch="1" adv="1">MS10-018</ref>
      <ref url="http://securitytracker.com/id?1023773" source="SECTRACK">1023773</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8532" source="OVAL">oval:org.mitre.oval:def:8532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0808" published="2010-10-13" name="CVE-2010-0808" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplete Information Disclosure Vulnerability."</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-071.mspx

'An attacker who successfully exploited this vulnerability could potentially capture data previously entered into forms in the browser. The AutoComplete feature is disabled by default.'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-071.mspx" source="MS" patch="1" adv="1">MS10-071</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100113324" source="CONFIRM">http://support.avaya.com/css/P8/documents/100113324</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6889" source="OVAL">oval:org.mitre.oval:def:6889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0810" published="2010-04-14" name="CVE-2010-0810" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-021.mspx" source="MS" patch="1" adv="1">MS10-021</ref>
      <ref url="http://www.securitytracker.com/id?1023850" source="SECTRACK">1023850</ref>
      <ref url="http://secunia.com/advisories/39373" source="SECUNIA">39373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7012" source="OVAL">oval:org.mitre.oval:def:7012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0811" published="2010-06-08" name="CVE-2010-0811" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-034.mspx" source="MS" patch="1" adv="1">MS10-034</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-027.mspx" source="MS">MS11-027</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7492" source="OVAL">oval:org.mitre.oval:def:7492</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12534" source="OVAL">oval:org.mitre.oval:def:12534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0812" published="2010-04-14" name="CVE-2010-0812" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103A.html" source="CERT">TA10-103A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-029.mspx" source="MS" patch="1" adv="1">MS10-029</ref>
      <ref url="http://secunia.com/advisories/39382" source="SECUNIA">39382</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7574" source="OVAL">oval:org.mitre.oval:def:7574</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0814" published="2010-07-15" name="CVE-2010-0814" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-194A.html" source="CERT">TA10-194A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-044.mspx" source="MS" patch="1" adv="1">MS10-044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11907" source="OVAL">oval:org.mitre.oval:def:11907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0815" published="2010-05-12" name="CVE-2010-0815" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-131A.html" source="CERT">TA10-131A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-031.mspx" source="MS" patch="1" adv="1">MS10-031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7074" source="OVAL">oval:org.mitre.oval:def:7074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="visual_basic_for_applications">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="visual_basic_sdk">
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0816" published="2010-05-12" name="CVE-2010-0816" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-131A.html" source="CERT">TA10-131A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-030.mspx" source="MS" patch="1" adv="1">MS10-030</ref>
      <ref url="http://www.securityfocus.com/bid/40052" source="BID">40052</ref>
      <ref url="http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=13&amp;Itemid=13" source="MISC">http://www.protekresearchlab.com/index.php?option=com_content&amp;view=article&amp;id=13&amp;Itemid=13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6734" source="OVAL">oval:org.mitre.oval:def:6734</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-05/0068.html" source="BUGTRAQ">20100511 {PRL} Microsoft Windows Outlook Express and Windows Mail Integer Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" edition="sp2" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_live_mail">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_mail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0817" published="2010-04-29" name="CVE-2010-0817" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511021/100/0/threaded" source="BUGTRAQ">20100428 XSS in Microsoft SharePoint Server 2007</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx" source="MS">MS10-039</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.html" source="MISC">http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7468" source="OVAL">oval:org.mitre.oval:def:7468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2007" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_services">
        <vers num="3.0" edition="sp1" />
        <vers num="3.0" edition="sp1:x32" />
        <vers num="3.0" edition="sp1:x64" />
        <vers num="3.0" edition="sp2" />
        <vers num="3.0" edition="sp2:x32" />
        <vers num="3.0" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0818" published="2010-09-15" name="CVE-2010-0818" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-062.mspx" source="MS" patch="1" adv="1">MS10-062</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7318" source="OVAL">oval:org.mitre.oval:def:7318</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0819" published="2010-06-08" name="CVE-2010-0819" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-037.mspx" source="MS" patch="1" adv="1">MS10-037</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58884" source="XF">win-opentype-cff-priv-escalation(58884)</ref>
      <ref url="http://www.securityfocus.com/bid/40572" source="BID">40572</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7072" source="OVAL">oval:org.mitre.oval:def:7072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0820" published="2010-09-15" name="CVE-2010-0820" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) in Windows Vista SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote authenticated users to execute arbitrary code via malformed LDAP messages, aka "LSASS Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-068.mspx" source="MS" patch="1" adv="1">MS10-068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7120" source="OVAL">oval:org.mitre.oval:def:7120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0821" published="2010-06-08" name="CVE-2010-0821" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with a crafted SxView record, related to improper validation of unspecified structures, aka "Excel Record Parsing Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-1245.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-104" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-104</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511729/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-104: Microsoft Office Excel SxView Record Parsing Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6771" source="OVAL">oval:org.mitre.oval:def:6771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0822" published="2010-06-08" name="CVE-2010-0822" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40520" source="BID">40520</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511752/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel OBJ Stack Overflow Vulnerability (CVE-2010-0822)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7265" source="OVAL">oval:org.mitre.oval:def:7265</ref>
      <ref url="http://osvdb.org/65236" source="OSVDB">65236</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0823" published="2010-06-08" name="CVE-2010-0823" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-1247 and CVE-2010-1249.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7240" source="OVAL">oval:org.mitre.oval:def:7240</ref>
      <ref url="http://osvdb.org/65233" source="OSVDB">65233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0824" published="2010-06-08" name="CVE-2010-0824" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40522" source="BID">40522</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511760/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel WOPT Heap Corruption Vulnerability (CVE-2010-0824)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6768" source="OVAL">oval:org.mitre.oval:def:6768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0825" published="2010-04-05" name="CVE-2010-0825" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+bug/531569" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+bug/531569</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57457" source="XF">emacs-emailhelper-symlink(57457)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0952" source="VUPEN">ADV-2010-0952</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0734" source="VUPEN" adv="1">ADV-2010-0734</ref>
      <ref url="http://www.ubuntu.com/usn/USN-919-1" source="UBUNTU">USN-919-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:083" source="MANDRIVA">MDVSA-2010:083</ref>
      <ref url="http://secunia.com/advisories/39155" source="SECUNIA" adv="1">39155</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="emacs">
        <vers num="22.1" />
        <vers num="22.2" />
        <vers num="22.3" />
        <vers num="23.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0826" published="2010-04-05" name="CVE-2010-0826" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/libnss-db/+bug/531976" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/libnss-db/+bug/531976</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0903" source="VUPEN">ADV-2010-0903</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0841" source="VUPEN">ADV-2010-0841</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0776" source="VUPEN" adv="1">ADV-2010-0776</ref>
      <ref url="http://www.ubuntu.com/usn/USN-922-1" source="UBUNTU">USN-922-1</ref>
      <ref url="http://www.securityfocus.com/bid/39132" source="BID">39132</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:077" source="MANDRIVA">MDVSA-2010:077</ref>
      <ref url="http://secunia.com/advisories/39165" source="SECUNIA" adv="1">39165</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6681" source="OVAL">oval:org.mitre.oval:def:6681</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10727" source="OVAL">oval:org.mitre.oval:def:10727</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038760.html" source="FEDORA">FEDORA-2010-6203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="piotr_roszatycki" name="libnss-db">
        <vers num="2.2.3" edition="pre1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0827" published="2010-05-07" name="CVE-2010-0827" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associated with a DVI file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572914" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572914</ref>
      <ref url="http://www.ubuntu.com/usn/USN-937-1" source="UBUNTU">USN-937-1</ref>
      <ref url="http://www.tug.org/svn/texlive/trunk/Build/source/texk/dvipsk/ChangeLog?view=log" source="CONFIRM">http://www.tug.org/svn/texlive/trunk/Build/source/texk/dvipsk/ChangeLog?view=log</ref>
      <ref url="http://www.tug.org/svn/texlive/trunk/Build/source/texk/dvipsk/ChangeLog?r1=18009&amp;r2=18095" source="CONFIRM">http://www.tug.org/svn/texlive/trunk/Build/source/texk/dvipsk/ChangeLog?r1=18009&amp;r2=18095</ref>
      <ref url="http://www.securityfocus.com/bid/39971" source="BID">39971</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-0827" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-0827</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10052" source="OVAL">oval:org.mitre.oval:def:10052</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tug" name="tetex">
        <vers num="" />
      </prod>
      <prod vendor="tug" name="tex_live">
        <vers num="1996" />
        <vers num="1998" />
        <vers num="1999" />
        <vers num="2000" />
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2007" />
        <vers num="2008" />
        <vers prev="1" num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0828" published="2010-04-05" name="CVE-2010-0828" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://hg.moinmo.in/moin/1.9/rev/6e603e5411ca" source="CONFIRM" patch="1">http://hg.moinmo.in/moin/1.9/rev/6e603e5411ca</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=578801" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=578801</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/moin/+bug/538022" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/moin/+bug/538022</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57435" source="XF">moinmoin-despam-xss(57435)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0834" source="VUPEN">ADV-2010-0834</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0831" source="VUPEN">ADV-2010-0831</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0767" source="VUPEN" adv="1">ADV-2010-0767</ref>
      <ref url="http://www.ubuntu.com/usn/USN-925-1" source="UBUNTU">USN-925-1</ref>
      <ref url="http://www.securityfocus.com/bid/39110" source="BID">39110</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2024" source="DEBIAN">DSA-2024</ref>
      <ref url="http://secunia.com/advisories/39284" source="SECUNIA">39284</ref>
      <ref url="http://secunia.com/advisories/39267" source="SECUNIA">39267</ref>
      <ref url="http://secunia.com/advisories/39190" source="SECUNIA" adv="1">39190</ref>
      <ref url="http://secunia.com/advisories/39188" source="SECUNIA" adv="1">39188</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038706.html" source="FEDORA">FEDORA-2010-6180</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038574.html" source="FEDORA">FEDORA-2010-6134</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038490.html" source="FEDORA">FEDORA-2010-6012</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575995" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.8.7" />
        <vers num="1.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0829" published="2010-05-07" name="CVE-2010-0829" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=573999" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=573999</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1219" source="VUPEN">ADV-2010-1219</ref>
      <ref url="http://www.ubuntu.com/usn/USN-936-1" source="UBUNTU">USN-936-1</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2048" source="DEBIAN">DSA-2048</ref>
      <ref url="http://secunia.com/advisories/39914" source="SECUNIA">39914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9718" source="OVAL">oval:org.mitre.oval:def:9718</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041587.html" source="FEDORA">FEDORA-2010-8279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jan-ake_larsson" name="dvipng">
        <vers num="1.11" />
        <vers num="1.12" />
      </prod>
      <prod vendor="tug" name="tetex">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0830" published="2010-06-01" name="CVE-2010-0830" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40063" source="BID" patch="1">40063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58915" source="XF">glibc-elf-code-execution(58915)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1246" source="VUPEN" adv="1">ADV-2010-1246</ref>
      <ref url="http://www.ubuntu.com/usn/USN-944-1" source="UBUNTU">USN-944-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:112" source="MANDRIVA">MDVSA-2010:112</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:111" source="MANDRIVA">MDVSA-2010:111</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2058" source="DEBIAN">DSA-2058</ref>
      <ref url="http://sourceware.org/git/?p=glibc.git;a=commit;h=db07e962b6ea963dbb345439f6ab9b0cf74d87c5" source="CONFIRM">http://sourceware.org/git/?p=glibc.git;a=commit;h=db07e962b6ea963dbb345439f6ab9b0cf74d87c5</ref>
      <ref url="http://securitytracker.com/id?1024044" source="SECTRACK">1024044</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201011-01.xml" source="GENTOO">GLSA-201011-01</ref>
      <ref url="http://secunia.com/advisories/39900" source="SECUNIA" adv="1">39900</ref>
      <ref url="http://frugalware.org/security/662" source="CONFIRM">http://frugalware.org/security/662</ref>
      <ref url="http://drosenbe.blogspot.com/2010/05/integer-overflow-in-ldso-cve-2010-0830.html" source="MISC">http://drosenbe.blogspot.com/2010/05/integer-overflow-in-ldso-cve-2010-0830.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="glibc">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.1.6" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.9" />
        <vers num="2.10" />
        <vers num="2.10.1" />
        <vers num="2.11" />
        <vers num="2.11.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0831" published="2010-06-18" name="CVE-2010-0831" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/540575" source="CONFIRM">https://launchpad.net/bugs/540575</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=601823" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=601823</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=594497" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=594497</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0121" source="VUPEN">ADV-2011-0121</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1553" source="VUPEN">ADV-2010-1553</ref>
      <ref url="http://www.securityfocus.com/bid/41006" source="BID">41006</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0025.html" source="REDHAT">RHSA-2011:0025</ref>
      <ref url="http://www.osvdb.org/65467" source="OSVDB">65467</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:122" source="MANDRIVA">MDVSA-2010:122</ref>
      <ref url="http://secunia.com/advisories/42892" source="SECUNIA">42892</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/f/fastjar/fastjar_0.98-3/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/f/fastjar/fastjar_0.98-3/changelog</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127603032617644&amp;w=2" source="MLIST">[oss-security] 20100608 Re: jar, fastjar directory traversal vulnerabilities</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127602731712034&amp;w=2" source="MLIST">[oss-security] 20100608 Re: jar, fastjar directory traversal vulnerabilities</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127602564508766&amp;w=2" source="MLIST">[oss-security] 20100608 jar, fastjar directory traversal vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthias_klose" name="fastjar">
        <vers num="0.98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0832" published="2010-07-12" name="CVE-2010-0832" modified="2010-07-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41465" source="BID" patch="1">41465</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/60194" source="XF">pammotd-motdlegalnotice-priv-escalation(60194)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1747" source="VUPEN" adv="1">ADV-2010-1747</ref>
      <ref url="http://www.ubuntu.com/usn/USN-959-1" source="UBUNTU" adv="1">USN-959-1</ref>
      <ref url="http://www.osvdb.org/66116" source="OSVDB">66116</ref>
      <ref url="http://www.h-online.com/security/news/item/Ubuntu-closes-root-hole-1034618.html" source="MISC">http://www.h-online.com/security/news/item/Ubuntu-closes-root-hole-1034618.html</ref>
      <ref url="http://www.exploit-db.com/exploits/14273" source="EXPLOIT-DB">14273</ref>
      <ref url="http://twitter.com/jonoberheide/statuses/18009527979" source="MISC">http://twitter.com/jonoberheide/statuses/18009527979</ref>
      <ref url="http://secunia.com/advisories/40512" source="SECUNIA" adv="1">40512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="10.04" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0833" published="2010-07-28" name="CVE-2010-0833" modified="2011-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.likewise.com/community/index.php/forums/viewthread/772/" source="CONFIRM" patch="1" adv="1">http://www.likewise.com/community/index.php/forums/viewthread/772/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0312" source="VUPEN" adv="1">ADV-2011-0312</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1913" source="VUPEN" adv="1">ADV-2010-1913</ref>
      <ref url="http://www.ubuntu.com/usn/USN-964-1" source="UBUNTU">USN-964-1</ref>
      <ref url="http://www.securitytracker.com/id?1025031" source="SECTRACK">1025031</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512643/100/0/threaded" source="BUGTRAQ">20100726 [LWSA-2010-001] Likewise Open 5.4 &amp; 6.0</ref>
      <ref url="http://secunia.com/advisories/43244" source="SECUNIA" adv="1">43244</ref>
      <ref url="http://secunia.com/advisories/40736" source="SECUNIA" adv="1">40736</ref>
      <ref url="http://secunia.com/advisories/40725" source="SECUNIA" adv="1">40725</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129719002806096&amp;w=2" source="HP">HPSBST02630</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129719002806096&amp;w=2" source="HP">HPSBST02630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="likewise" name="likewise_cifs">
        <vers num="5.4" />
      </prod>
      <prod vendor="likewise" name="likewise_open">
        <vers num="5.4" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0834" published="2010-08-10" name="CVE-2010-0834" modified="2010-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42280" source="BID" patch="1">42280</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2015" source="VUPEN" adv="1">ADV-2010-2015</ref>
      <ref url="http://www.ubuntu.com/usn/usn-968-1" source="UBUNTU">USN-968-1</ref>
      <ref url="http://secunia.com/advisories/40889" source="SECUNIA" adv="1">40889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="10.04" edition="-" />
        <vers num="10.04" edition="-:lts" />
        <vers num="9.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0835" published="2010-07-13" name="CVE-2010-0835" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Wireless component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0836" published="2010-07-13" name="CVE-2010-0836" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0837" published="2010-04-01" name="CVE-2010-0837" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Pack200 component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14276" source="OVAL">oval:org.mitre.oval:def:14276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10680" source="OVAL">oval:org.mitre.oval:def:10680</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0838" published="2010-04-01" name="CVE-2010-0838" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow using an untrusted size value in the readMabCurveData function in the CMM module in the JVM.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57346" source="XF">javase-javab-java2d-unspecifed(57346)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-061" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-061</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN" adv="1">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39069" source="BID">39069</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510534/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-061: Sun Java Runtime CMM readMabCurveData Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA" adv="1">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13923" source="OVAL">oval:org.mitre.oval:def:13923</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10482" source="OVAL">oval:org.mitre.oval:def:10482</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0839" published="2010-04-01" name="CVE-2010-0839" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13357" source="OVAL">oval:org.mitre.oval:def:13357</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0840" published="2010-04-01" name="CVE-2010-0840" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-056" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-056</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39065" source="BID">39065</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510528/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA" adv="1">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9974" source="OVAL">oval:org.mitre.oval:def:9974</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13971" source="OVAL">oval:org.mitre.oval:def:13971</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0841" published="2010-04-01" name="CVE-2010-0841" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the Java Runtime Environment that allows remote attackers to execute arbitrary code via a JPEG image that contains subsample dimensions with large values, related to JPEGImageReader and "stepX".</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-054/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-054/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39067" source="BID">39067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510531/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-054: Sun Java Runtime Environment JPEGImageReader stepX Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14144" source="OVAL">oval:org.mitre.oval:def:14144</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0842" published="2010-04-01" name="CVE-2010-0842" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an uncontrolled array index that allows remote attackers to execute arbitrary code via a MIDI file with a crafted MixerSequencer object, related to the GM_Song structure.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-060" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-060</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39077" source="BID">39077</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510532/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-060: Sun Java Runtime Environment MixerSequencer Invalid Array Index Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14101" source="OVAL">oval:org.mitre.oval:def:14101</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0843" published="2010-04-01" name="CVE-2010-0843" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-052/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-052/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39083" source="BID">39083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://seclists.org/bugtraq/2010/Apr/41" source="BUGTRAQ">20100405 ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14092" source="OVAL">oval:org.mitre.oval:def:14092</ref>
      <ref url="http://osvdb.org/63492" source="OSVDB">63492</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.5.0" edition="update23" />
        <vers num="1.6.0" edition="update_18" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.1_27" />
        <vers num="1.4.2_25" />
        <vers num="1.5.0" edition="update23" />
        <vers num="1.6.0" edition="update_18" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.1_27" />
        <vers num="1.4.2_25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0844" published="2010-04-01" name="CVE-2010-0844" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is for improper parsing of a crafted MIDI stream when creating a MixerSequencer object, which causes a pointer to be corrupted and allows a NULL byte to be written to arbitrary memory.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-053" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-053</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510529/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-053: Sun Java Runtime Environment MIDI File metaEvent Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14282" source="OVAL">oval:org.mitre.oval:def:14282</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0845" published="2010-04-01" name="CVE-2010-0845" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the HotSpot Server component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9896" source="OVAL">oval:org.mitre.oval:def:9896</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14521" source="OVAL">oval:org.mitre.oval:def:14521</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0846" published="2010-04-01" name="CVE-2010-0846" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the ImageIO component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows remote attackers to execute arbitrary code, related to an "invalid assignment" and inconsistent length values in a JPEG image encoder (JPEGImageEncoderImpl).</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-059" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-059</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39062" source="BID">39062</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510541/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-059: Sun Java Runtime Environment JPEGImageEncoderImpl Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14503" source="OVAL">oval:org.mitre.oval:def:14503</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0847" published="2010-04-01" name="CVE-2010-0847" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow that allows arbitrary code execution via a crafted image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39071" source="BID">39071</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14453" source="OVAL">oval:org.mitre.oval:def:14453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10392" source="OVAL">oval:org.mitre.oval:def:10392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=865" source="IDEFENSE">20100330 Oracle Java Runtime Environment Image FIle Buffer Overflow Vulnerability</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">HPSBMA02547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update22" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update22" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0848" published="2010-04-01" name="CVE-2010-0848" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
      <descript source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html



'Affected product releases and versions:
• Java SE: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
	    

        • JDK 5.0 Update 23 and earlier for Solaris
	  

        • SDK 1.4.2_25 and earlier for Solaris
	  
• Java for Business: 	 

        • JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
	  

        • JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
	  

        • SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39078" source="BID">39078</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0339.html" source="REDHAT">RHSA-2010:0339</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:084" source="MANDRIVA">MDVSA-2010:084</ref>
      <ref url="http://ubuntu.com/usn/usn-923-1" source="UBUNTU">USN-923-1</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://secunia.com/advisories/39292" source="SECUNIA">39292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9899" source="OVAL">oval:org.mitre.oval:def:9899</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14350" source="OVAL">oval:org.mitre.oval:def:14350</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0849" published="2010-04-01" name="CVE-2010-0849" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the March 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is a heap-based buffer overflow in a decoding routine used by the JPEGImageDecoderImpl interface, which allows code execution via a crafted JPEG image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-057/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-057/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN" adv="1">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1523" source="VUPEN" adv="1">ADV-2010-1523</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1454" source="VUPEN" adv="1">ADV-2010-1454</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN" adv="1">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39073" source="BID">39073</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510548/100/0/threaded" source="BUGTRAQ">20100405 ZDI-10-057: Sun Java Runtime Environment JPEGImageDecoderImpl Remote Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0489.html" source="REDHAT">RHSA-2010:0489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0471.html" source="REDHAT">RHSA-2010:0471</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0383.html" source="REDHAT">RHSA-2010:0383</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0338.html" source="REDHAT">RHSA-2010:0338</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0337.html" source="REDHAT">RHSA-2010:0337</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA" adv="1">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA" adv="1">40545</ref>
      <ref url="http://secunia.com/advisories/40211" source="SECUNIA" adv="1">40211</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA" adv="1">39819</ref>
      <ref url="http://secunia.com/advisories/39659" source="SECUNIA" adv="1">39659</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA" adv="1">39317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13795" source="OVAL">oval:org.mitre.oval:def:13795</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update22" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update1" />
        <vers prev="1" num="1.6.0" edition="update1_b06" />
        <vers prev="1" num="1.6.0" edition="update2" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" edition="update1" />
        <vers num="1.4.2" edition="update2" />
        <vers num="1.4.2" edition="update3" />
        <vers num="1.4.2" edition="update4" />
        <vers num="1.4.2" edition="update5" />
        <vers num="1.4.2" edition="update6" />
        <vers num="1.4.2" edition="update7" />
        <vers num="1.4.2" edition="update8" />
        <vers num="1.4.2" edition="update9" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update22" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.6.0" edition="update_1" />
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_11" />
        <vers prev="1" num="1.6.0" edition="update_12" />
        <vers prev="1" num="1.6.0" edition="update_13" />
        <vers prev="1" num="1.6.0" edition="update_14" />
        <vers prev="1" num="1.6.0" edition="update_15" />
        <vers prev="1" num="1.6.0" edition="update_16" />
        <vers prev="1" num="1.6.0" edition="update_17" />
        <vers prev="1" num="1.6.0" edition="update_18" />
        <vers prev="1" num="1.6.0" edition="update_2" />
        <vers prev="1" num="1.6.0" edition="update_3" />
        <vers prev="1" num="1.6.0" edition="update_4" />
        <vers prev="1" num="1.6.0" edition="update_5" />
        <vers prev="1" num="1.6.0" edition="update_6" />
        <vers prev="1" num="1.6.0" edition="update_7" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
        <vers num="1.4.2" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_20" />
        <vers num="1.4.2_21" />
        <vers num="1.4.2_22" />
        <vers num="1.4.2_23" />
        <vers num="1.4.2_24" />
        <vers prev="1" num="1.4.2_25" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0850" published="2010-04-01" name="CVE-2010-0850" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://secunia.com/advisories/43308" source="SECUNIA">43308</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" edition="update1" />
        <vers num="1.3.0" edition="update2" />
        <vers num="1.3.0" edition="update3" />
        <vers num="1.3.0" edition="update4" />
        <vers num="1.3.0" edition="update5" />
        <vers num="1.3.1" edition="update1" />
        <vers num="1.3.1" edition="update2" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_2" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
      </prod>
      <prod vendor="sun" name="sdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers prev="1" num="1.3.1_27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0851" published="2010-04-13" name="CVE-2010-0851" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0852" published="2010-04-13" name="CVE-2010-0852" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0853" published="2010-04-13" name="CVE-2010-0853" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8, 9.2.0.8, and DV; and Oracle Fusion Middleware 10.1.2.3 and 10.1.4.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0854" published="2010-04-13" name="CVE-2010-0854" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Audit component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to "SELECT, INSERT or DELETE on tables subject to auditing."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0855" published="2010-04-13" name="CVE-2010-0855" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023869" source="SECTRACK">1023869</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0856" published="2010-04-13" name="CVE-2010-0856" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.2 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023869" source="SECTRACK">1023869</ref>
      <ref url="http://www.securityfocus.com/bid/39442" source="BID">39442</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0857" published="2010-04-13" name="CVE-2010-0857" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Workflow Cartridge component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0858" published="2010-04-13" name="CVE-2010-0858" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0859" published="2010-04-13" name="CVE-2010-0859" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 ATG RUP6 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" edition="atg_rup6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0860" published="2010-04-13" name="CVE-2010-0860" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to the Create User privilege.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0861" published="2010-04-13" name="CVE-2010-0861" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HRMS (Self Service) component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0862" published="2010-04-13" name="CVE-2010-0862" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Retail - Oracle Retail Markdown Optimization component in Oracle Industry Product Suite 13.1 allows remote attackers to affect integrity via unknown vectors related to Online Help.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html

'1. For Oracle Retail Markdown Optimization, Plan, and Place In-Season, this vulnerability affects the Online Help and not the actual applications.'</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57742" source="XF">oipsr-rmo-unspecifed(57742)</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
      <ref url="http://www.securityfocus.com/bid/39444" source="BID">39444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="13.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0863" published="2010-04-13" name="CVE-2010-0863" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Retail - Oracle Retail Plan In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57744" source="XF">oipsr-rplanis-unspecified(57744)</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="12.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0864" published="2010-04-13" name="CVE-2010-0864" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Retail - Oracle Retail Place In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html#AppendixBU

'1. For Oracle Retail Markdown Optimization, Plan, and Place In-Season, this vulnerability affects the Online Help and not the actual applications.'</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57743" source="XF">oipsr-rplaceis-unspecified(57743)</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="12.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0865" published="2010-04-13" name="CVE-2010-0865" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="6.1.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0866" published="2010-04-13" name="CVE-2010-0866" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0867" published="2010-04-13" name="CVE-2010-0867" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0868" published="2010-04-13" name="CVE-2010-0868" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0869" published="2010-04-13" name="CVE-2010-0869" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Transportation Management component in Oracle E-Business Suite 5.5.05.07, 5.5.06.00, and 6.0.03 allows remote attackers to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="5.5.05.07" />
        <vers num="5.5.06.00" />
        <vers num="6.0.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0870" published="2010-04-13" name="CVE-2010-0870" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39438" source="SECUNIA">39438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0871" published="2010-04-13" name="CVE-2010-0871" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023859" source="SECTRACK">1023859</ref>
      <ref url="http://secunia.com/advisories/39441" source="SECUNIA">39441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0872" published="2010-04-13" name="CVE-2010-0872" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Internet Directory component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://secunia.com/advisories/39439" source="SECUNIA">39439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="fusion_middleware">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0873" published="2010-07-13" name="CVE-2010-0873" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Data Server component in Oracle TimesTen In-Memory Database 7.0.6.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="timesten_in-memory_database">
        <vers num="7.0.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0874" published="2010-04-13" name="CVE-2010-0874" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Communications - Oracle Communications Unified Inventory Management component in Oracle Industry Product Suite 7.1 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0875" published="2010-04-13" name="CVE-2010-0875" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Life Sciences - Oracle Thesaurus Management System component in Oracle Industry Product Suite 4.5.2, 4.6, and 4.6.1 allows remote attackers to affect integrity, related to TMS Browser.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="4.5.2" />
        <vers num="4.6" />
        <vers num="4.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0876" published="2010-04-13" name="CVE-2010-0876" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Life Sciences - Oracle Clinical Remote Data Capture Option component in Oracle Industry Product Suite 4.5.3 and 4.6 allows remote attackers to affect integrity, related to RDC Onsite.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023872" source="SECTRACK">1023872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="industry_product_suite">
        <vers num="4.5.3" />
        <vers num="4.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0877" published="2010-04-13" name="CVE-2010-0877" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57736" source="XF">opejee-peopletools-unspecified-var1(57736)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0878" published="2010-04-13" name="CVE-2010-0878" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57737" source="XF">opejee-peopletools-unspecified-var2(57737)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0879" published="2010-04-13" name="CVE-2010-0879" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57738" source="XF">opejee-peopletools-unspecified-var3(57738)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0880" published="2010-04-13" name="CVE-2010-0880" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57735" source="XF">opejee-peopletools-unspecified(57735)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="8.49.26" />
        <vers num="8.50.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0881" published="2010-04-14" name="CVE-2010-0881" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the User Interface Components in Oracle Collaboration Suite 10.1.2.4 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.securitytracker.com/id?1023871" source="SECTRACK">1023871</ref>
      <ref url="http://www.securityfocus.com/bid/39447" source="BID">39447</ref>
      <ref url="http://secunia.com/advisories/39440" source="SECUNIA">39440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="10.1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0882" published="2010-04-13" name="CVE-2010-0882" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Trusted Extensions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57747" source="XF">osps-solaris-unspecified(57747)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020726.1-1" source="SUNALERT">1020726</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7023" source="OVAL">oval:org.mitre.oval:def:7023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="10" />
      </prod>
      <prod vendor="oracle" name="opensolaris">
        <vers num="snv_134" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0883" published="2010-04-13" name="CVE-2010-0883" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57759" source="XF">osps-cluster-unspecified(57759)</ref>
      <ref url="http://www.securityfocus.com/bid/39460" source="BID">39460</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021808.1-1" source="SUNALERT">1021808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0884" published="2010-04-13" name="CVE-2010-0884" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57760" source="XF">osps-cluster-unspecified-var1(57760)</ref>
      <ref url="http://www.securityfocus.com/bid/39464" source="BID">39464</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021808.1-1" source="SUNALERT">1021808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0885" published="2010-04-13" name="CVE-2010-0885" modified="2010-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Java System Communications Express component in Oracle Sun Product Suite 6 2005Q4 (6.2) and and 6.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Address Book.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022024.1-1" source="SUNALERT">1022024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="6.2" />
        <vers num="6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0886" published="2010-04-20" name="CVE-2010-0886" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html

'Notes:

   1. Affects the Windows platform only. CVSS 10.0 score assumes running with Administrator privileges. Otherwise, CVSS score of 7.5 with Confidentiality, Integrity and Availability impacts of Partial+, Partial+ and Partial+.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1" source="SUNALERT">1022294</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1" source="SUNALERT">279590</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14216" source="OVAL">oval:org.mitre.oval:def:14216</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.6.0" edition="update10" />
        <vers num="1.6.0" edition="update11" />
        <vers num="1.6.0" edition="update12" />
        <vers num="1.6.0" edition="update13" />
        <vers num="1.6.0" edition="update14" />
        <vers num="1.6.0" edition="update15" />
        <vers num="1.6.0" edition="update16" />
        <vers num="1.6.0" edition="update17" />
        <vers num="1.6.0" edition="update18" />
        <vers num="1.6.0" edition="update19" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.6.0" edition="update10" />
        <vers num="1.6.0" edition="update11" />
        <vers num="1.6.0" edition="update12" />
        <vers num="1.6.0" edition="update13" />
        <vers num="1.6.0" edition="update14" />
        <vers num="1.6.0" edition="update15" />
        <vers num="1.6.0" edition="update16" />
        <vers num="1.6.0" edition="update17" />
        <vers num="1.6.0" edition="update18" />
        <vers num="1.6.0" edition="update19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0887" published="2010-04-20" name="CVE-2010-0887" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://support.apple.com/kb/HT4170" source="CONFIRM">http://support.apple.com/kb/HT4170</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00002.html" source="APPLE">APPLE-SA-2010-05-18-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="6" edition="18" />
        <vers num="6" edition="18:se" />
        <vers num="6" edition="18:business" />
        <vers num="6" edition="19" />
        <vers num="6" edition="19:business" />
        <vers num="6" edition="19:se" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0888" published="2010-04-13" name="CVE-2010-0888" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Ray Server Software component in Oracle Sun Product Suite 4.0, 4.1, and 4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Device Services.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57745" source="XF">osps-srss-unspecified(57745)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021732.1-1" source="SUNALERT">1021732</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-274590-1" source="SUNALERT">274590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0889" published="2010-04-13" name="CVE-2010-0889" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_68 through snv_128 allows local users to affect confidentiality via unknown vectors related to the Kernel.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57754" source="XF">osps-solars-unspecified-var1(57754)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021697.1-1" source="SUNALERT">1021697</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-273850-1" source="SUNALERT">273850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensolaris">
        <vers num="snv_128" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0890" published="2010-04-13" name="CVE-2010-0890" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_01 through snv_98 allows local users to affect availability via unknown vectors related to the Kernel.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57758" source="XF">osps-solaris-unspecified-var3(57758)</ref>
      <ref url="http://www.securitytracker.com/id?1023874" source="SECTRACK">1023874</ref>
      <ref url="http://www.securityfocus.com/bid/39459" source="BID">39459</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019619.1-1" source="SUNALERT">1019619</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-242386-1" source="SUNALERT">242386</ref>
      <ref url="http://secunia.com/advisories/39435" source="SECUNIA">39435</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7594" source="OVAL">oval:org.mitre.oval:def:7594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="10" />
      </prod>
      <prod vendor="oracle" name="opensolaris">
        <vers num="snv_98" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0891" published="2010-04-13" name="CVE-2010-0891" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57751" source="XF">osps-smc-unspecified(57751)</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019908.1-1" source="SUNALERT">1019908</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248666-1" source="SUNALERT">248666</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7233" source="OVAL">oval:org.mitre.oval:def:7233</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="3.6.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0892" published="2010-07-13" name="CVE-2010-0892" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'For patching information please see Critical Patch Update July 2010 Patch Availability Document for Oracle Products, My Oracle Support Note 1089044.1.'</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="3.2.0.00.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0893" published="2010-04-13" name="CVE-2010-0893" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57756" source="XF">osps-converge-unspecified(57756)</ref>
      <ref url="http://www.securityfocus.com/bid/39446" source="BID">39446</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021807.1-1" source="SUNALERT">1021807</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-276090-1" source="SUNALERT">276090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0894" published="2010-04-13" name="CVE-2010-0894" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Java System Access Manager component in Oracle Sun Product Suite 7.1, 7 2005Q4, and OpenSSO Enterprise 8.0 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57750" source="XF">osps-sjsa-unspecified(57750)</ref>
      <ref url="http://www.securityfocus.com/bid/39457" source="BID">39457</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020934.1-1" source="SUNALERT">1020934</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-267568-1" source="SUNALERT">267568</ref>
      <ref url="http://secunia.com/advisories/39431" source="SECUNIA">39431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensso_enterprise">
        <vers num="8.0" />
      </prod>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="7" edition="2005q4" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0895" published="2010-04-13" name="CVE-2010-0895" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_119 allows local users to affect integrity and availability via unknown vectors related to IP Filter.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57757" source="XF">osps-solaris-unspecified-var2(57757)</ref>
      <ref url="http://www.securityfocus.com/bid/39455" source="BID">39455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensolaris">
        <vers num="snv_119" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0896" published="2010-04-13" name="CVE-2010-0896" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Address Book and Mail Filter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57748" source="XF">osps-convergence-unspecified(57748)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0897" published="2010-04-13" name="CVE-2010-0897" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Sun Java System Directory Server component in Oracle Sun Product Suite 5.2, 6.0, 6.1, 6.2, 6.3, and 6.3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Directory Service Markup Language.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57746" source="XF">osps-sjsds-unspecified(57746)</ref>
      <ref url="http://www.securityfocus.com/bid/39453" source="BID">39453</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-276210-1" source="SUNALERT">276210</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_product_suite">
        <vers num="5.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0898" published="2010-07-13" name="CVE-2010-0898" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0899" published="2010-07-13" name="CVE-2010-0899" modified="2010-07-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0907, and CVE-2010-0906.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'This bug is applicable to Windows only.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0900" published="2010-07-13" name="CVE-2010-0900" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Network Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'Oracle Database Server Client-Only Installations

The following Oracle Database Server vulnerability included in this Critical Patch Update affects client-only installations: CVE-2010-0900'</impact>
    </impacts>
    <sols>
      <sol source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'For patching information please see Critical Patch Update July 2010 Patch Availability Document for Oracle Products, My Oracle Support Note 1089044.1.'</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
        <vers num="9.2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0901" published="2010-07-13" name="CVE-2010-0901" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Select Any Dictionary.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0902" published="2010-07-13" name="CVE-2010-0902" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0903" published="2010-07-13" name="CVE-2010-0903" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Net Foundation Layer component in Oracle Database Server 9.2.0.8, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1, when running on Windows, allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'For patching information please see Critical Patch Update July 2010 Patch Availability Document for Oracle Products, My Oracle Support Note 1089044.1.'</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
        <vers num="9.2.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0904" published="2010-07-13" name="CVE-2010-0904" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://securityreason.com/securityalert/8356" source="SREASON">8356</ref>
      <ref url="http://securityreason.com/securityalert/8354" source="SREASON">8354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0905" published="2010-07-13" name="CVE-2010-0905" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0906" published="2010-07-13" name="CVE-2010-0906" modified="2010-07-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'CVSS Score is 9.0 for Windows based installation. For Linux, Unix and other platforms, the CVSS Base Score is 6.5, and the impacts for Confidentiality, Integrity and Availability are Partial.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0907" published="2010-07-13" name="CVE-2010-0907" modified="2010-07-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0899, CVE-2010-0904, and CVE-2010-0906.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html

'CVSS Score is 10.0 for Windows based installation. For Linux, Unix and other platforms, the CVSS Base Score is 7.5, and the impacts for Confidentiality, Integrity and Availability are Partial.'</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="secure_backup">
        <vers num="10.3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0908" published="2010-07-13" name="CVE-2010-0908" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0909" published="2010-07-13" name="CVE-2010-0909" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0910" published="2010-07-13" name="CVE-2010-0910" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Data Server component in Oracle TimesTen In-Memory Database 7.0.6.0 and 11.2.1.4.1 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="timesten_in-memory_database">
        <vers num="11.2.1.4.1" />
        <vers num="7.0.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0911" published="2010-07-13" name="CVE-2010-0911" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Listener component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="11.2.0.1" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0912" published="2010-07-13" name="CVE-2010-0912" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0913" published="2010-07-13" name="CVE-2010-0913" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0914" published="2010-07-13" name="CVE-2010-0914" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail, Calendar, Address Book, and Instant Messaging.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="sun_convergence">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0915" published="2010-07-13" name="CVE-2010-0915" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Advanced Product Catalog component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10.2" />
        <vers num="12.0.6" />
        <vers num="12.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0916" published="2010-07-13" name="CVE-2010-0916" modified="2010-07-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to rdist.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="opensolaris">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0917" published="2010-03-03" name="CVE-2010-0917" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56560" source="XF">ms-win-winhlp32-bo(56560)</ref>
      <ref url="http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/" source="MISC">http://www.theregister.co.uk/2010/03/01/ie_code_execution_bug/</ref>
      <ref url="http://www.securityfocus.com/bid/38473" source="BID">38473</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/981169.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/981169.mspx</ref>
      <ref url="http://isec.pl/vulnerabilities10.html" source="MISC">http://isec.pl/vulnerabilities10.html</ref>
      <ref url="http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt" source="MISC">http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2010/03/01/security-advisory-981169-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0918" published="2010-03-03" name="CVE-2010-0918" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56557" source="XF">inotes-ultralite-unspecified(56557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0496" source="VUPEN" adv="1">ADV-2010-0496</ref>
      <ref url="http://www.securityfocus.com/bid/38459" source="BID">38459</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27018109" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27018109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers num="229.231" />
        <vers num="229.241" />
        <vers num="229.251" />
        <vers num="229.261" />
        <vers prev="1" num="229.271" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0919" published="2010-03-03" name="CVE-2010-0919" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0496" source="VUPEN" patch="1" adv="1">ADV-2010-0496</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56555" source="XF">inotes-activex-bo(56555)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0495" source="VUPEN" adv="1">ADV-2010-0495</ref>
      <ref url="http://www.securityfocus.com/bid/38459" source="BID">38459</ref>
      <ref url="http://www.securityfocus.com/bid/38457" source="BID">38457</ref>
      <ref url="http://www.osvdb.org/62612" source="OSVDB">62612</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27018109" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27018109</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21421808" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21421808</ref>
      <ref url="http://securitytracker.com/id?1023662" source="SECTRACK">1023662</ref>
      <ref url="http://secunia.com/advisories/38755" source="SECUNIA" adv="1">38755</ref>
      <ref url="http://secunia.com/advisories/38744" source="SECUNIA" adv="1">38744</ref>
      <ref url="http://secunia.com/advisories/38681" source="SECUNIA" adv="1">38681</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=857" source="IDEFENSE">20100301 IBM Lotus Domino Web Access ActiveX Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="domino_web_access">
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="8.0" />
        <vers num="8.0.2" />
      </prod>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers num="229.231" />
        <vers num="229.241" />
        <vers num="229.251" />
        <vers num="229.261" />
        <vers prev="1" num="229.271" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0920" published="2010-03-03" name="CVE-2010-0920" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0496" source="VUPEN" adv="1">ADV-2010-0496</ref>
      <ref url="http://www.securityfocus.com/bid/38459" source="BID">38459</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27018109" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27018109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers num="229.231" />
        <vers num="229.241" />
        <vers num="229.251" />
        <vers num="229.261" />
        <vers prev="1" num="229.271" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0921" published="2010-03-03" name="CVE-2010-0921" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56556" source="XF">inotes-getfilter-csrf(56556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0496" source="VUPEN" adv="1">ADV-2010-0496</ref>
      <ref url="http://www.securityfocus.com/bid/38459" source="BID">38459</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27018109" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27018109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_inotes">
        <vers num="229.011" />
        <vers num="229.021" />
        <vers num="229.031" />
        <vers num="229.041" />
        <vers num="229.051" />
        <vers num="229.061" />
        <vers num="229.101" />
        <vers num="229.111" />
        <vers num="229.131" />
        <vers num="229.141" />
        <vers num="229.151" />
        <vers num="229.161" />
        <vers num="229.171" />
        <vers num="229.181" />
        <vers num="229.191" />
        <vers num="229.201" />
        <vers num="229.211" />
        <vers num="229.221" />
        <vers num="229.231" />
        <vers num="229.241" />
        <vers num="229.251" />
        <vers num="229.261" />
        <vers prev="1" num="229.271" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0922" published="2010-03-03" name="CVE-2010-0922" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in secldapclntd in IBM AIX 5.3 with SP 5300-11-02 allows attackers to cause a denial of service (LDAP login failure) via unknown vectors.  NOTE: some of these details are obtained from third party information.  NOTE: there may be no attacker role, and the issue may be triggered entirely by an administrator's installation of an official service pack.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per:
ftp://public.dhe.ibm.com/aix/efixes/iz69977/
IZ69977.epkg.Z</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4956" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4956</ref>
      <ref url="http://www.securityfocus.com/bid/38444" source="BID">38444</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ69977" source="AIXAPAR">IZ69977</ref>
      <ref url="ftp://public.dhe.ibm.com/aix/efixes/iz69977/README.txt" source="CONFIRM">ftp://public.dhe.ibm.com/aix/efixes/iz69977/README.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" edition="sp5300-11-02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0923" published="2010-03-03" name="CVE-2010-0923" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0409" source="VUPEN" patch="1" adv="1">ADV-2010-0409</ref>
      <ref url="http://websvn.kde.org/?view=revision&amp;revision=1089241" source="CONFIRM" patch="1">http://websvn.kde.org/?view=revision&amp;revision=1089241</ref>
      <ref url="http://websvn.kde.org/?revision=1089213&amp;view=revision" source="CONFIRM" patch="1">http://websvn.kde.org/?revision=1089213&amp;view=revision</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=579280" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=579280</ref>
      <ref url="https://bugs.kde.org/show_bug.cgi?id=217882" source="CONFIRM">https://bugs.kde.org/show_bug.cgi?id=217882</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/17/3" source="MLIST">[oss-security] 20100217 Re: Re: CVE Request: KDE screensaver unlock issue similar to GNOME one</ref>
      <ref url="http://www.kde.org/info/security/advisory-20100217-1.txt" source="CONFIRM">http://www.kde.org/info/security/advisory-20100217-1.txt</ref>
      <ref url="http://websvn.kde.org/trunk/KDE/kdebase/workspace/krunner/lock/lockdlg.cc?r1=1089213&amp;r2=1089212&amp;pathrev=1089213" source="CONFIRM">http://websvn.kde.org/trunk/KDE/kdebase/workspace/krunner/lock/lockdlg.cc?r1=1089213&amp;r2=1089212&amp;pathrev=1089213</ref>
      <ref url="http://securitytracker.com/id?1023641" source="SECTRACK">1023641</ref>
      <ref url="http://secunia.com/advisories/38600" source="SECUNIA" adv="1">38600</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126600468622421&amp;w=2" source="MLIST">[oss-security] 20100212 Re: Re: CVE Request: KDE screensaver unlock issue similar to GNOME one</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126599909614401&amp;w=2" source="MLIST">[oss-security] 20100212 Re: CVE Request: KDE screensaver unlock issue similar to GNOME one</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126598163422670&amp;w=2" source="MLIST">[oss-security] 20100212 CVE Request: KDE screensaver unlock issue similar to GNOME one</ref>
      <ref url="http://bugs.kde.org/show_bug.cgi?id=226449" source="CONFIRM">http://bugs.kde.org/show_bug.cgi?id=226449</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde_sc">
        <vers num="4.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0924" published="2010-03-03" name="CVE-2010-0924" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38447" source="BID">38447</ref>
      <ref url="http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txt" source="MISC">http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.3" />
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0925" published="2010-03-03" name="CVE-2010-0925" modified="2010-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the SRC attribute of a (1) IMG or (2) IFRAME element.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txt" source="MISC">http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0926" published="2010-03-10" name="CVE-2010-0926" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=7104" source="CONFIRM">https://bugzilla.samba.org/show_bug.cgi?id=7104</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=562568" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=562568</ref>
      <ref url="http://www.samba.org/samba/news/symlink_attack.html" source="CONFIRM" adv="1">http://www.samba.org/samba/news/symlink_attack.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/05/3" source="MLIST">[oss-security] 20100305 Re: Samba symlink 0day flaw</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/06/3" source="MLIST">[oss-security] 20100206 Re: Samba symlink 0day flaw</ref>
      <ref url="http://secunia.com/advisories/39317" source="SECUNIA">39317</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126555346721629&amp;w=2" source="MLIST">[samba-technical] 20100207 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126549111204428&amp;w=2" source="MLIST">[samba-technical] 20100206 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126548356728379&amp;w=2" source="MLIST">[samba-technical] 20100206 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126547903723628&amp;w=2" source="MLIST">[samba-technical] 20100206 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540695819735&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540608318301&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540539117328&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540477016522&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540475116511&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540376915283&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540290614053&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540277713815&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540248613395&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540100511357&amp;w=2" source="MLIST">[samba-technical] 20100205 Re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126540011609753&amp;w=2" source="MLIST">[samba-technical] 20100205 re: Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=samba-technical&amp;m=126539387432412&amp;w=2" source="MLIST">[samba-technical] 20100205 Claimed Zero Day exploit in Samba.</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126777580624790&amp;w=2" source="MLIST">[oss-security] 20100305 Re: Samba symlink 0day flaw</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126545363428745&amp;w=2" source="MLIST">[oss-security] 20100206 Re: Samba symlink 0day flaw</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126540733320471&amp;w=2" source="MLIST">[oss-security] 20100205 Re: Samba symlink 0day flaw</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126540402215620&amp;w=2" source="MLIST">[oss-security] 20100205 Re: Samba symlink 0day flaw</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126539592603079&amp;w=2" source="MLIST">[oss-security] 20100205 Samba symlink 0day flaw</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=126538598820903&amp;w=2" source="FULLDISC">20100205 Re: Samba Remote Zero-Day Exploit</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html" source="SUSE">SUSE-SR:2010:008</ref>
      <ref url="http://gitweb.samba.org/?p=samba.git;a=commit;h=bd269443e311d96ef495a9db47d1b95eb83bb8f4" source="CONFIRM">http://gitweb.samba.org/?p=samba.git;a=commit;h=bd269443e311d96ef495a9db47d1b95eb83bb8f4</ref>
      <ref url="http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html" source="MISC">http://blog.metasploit.com/2010/02/exploiting-samba-symlink-traversal.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0108.html" source="FULLDISC">20100204 Re: Samba Remote Zero-Day Exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0107.html" source="FULLDISC">20100204 Re: Samba Remote Zero-Day Exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0083.html" source="FULLDISC">20100204 Samba Remote Zero-Day Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.10" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.3.9" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0927" published="2010-03-05" name="CVE-2010-0927" modified="2010-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action.  NOTE: this may overlap CVE-2010-0920.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38481" source="BID">38481</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC_Advisory_2010_0301_IBM_%20Lotus_Dominio_Readme_nsf_Reflected_XSS.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC_Advisory_2010_0301_IBM_%20Lotus_Dominio_Readme_nsf_Reflected_XSS.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.1.1" />
        <vers num="7.0.2" />
        <vers num="7.0.2.1" />
        <vers num="7.0.2.2" />
        <vers num="7.0.2.3" />
        <vers num="7.0.3" />
        <vers num="7.0.3.1" />
        <vers num="8.0" />
        <vers num="8.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0928" published="2010-03-05" name="CVE-2010-0928" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it easier for physically proximate attackers to determine the private key via a modified supply voltage for the microprocessor, related to a "fault-based attack."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56750" source="XF">openssl-fwe-weak-security(56750)</ref>
      <ref url="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/" source="MISC">http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/</ref>
      <ref url="http://www.osvdb.org/62808" source="OSVDB">62808</ref>
      <ref url="http://www.networkworld.com/news/2010/030410-rsa-security-attack.html" source="MISC">http://www.networkworld.com/news/2010/030410-rsa-security-attack.html</ref>
      <ref url="http://www.eecs.umich.edu/%7Evaleria/research/publications/DATE10RSA.pdf" source="MISC">http://www.eecs.umich.edu/%7Evaleria/research/publications/DATE10RSA.pdf</ref>
      <ref url="http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/" source="MISC">http://rdist.root.org/2010/03/08/attacking-rsa-exponentiation-with-fault-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0929" published="2010-03-05" name="CVE-2010-0929" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0930" published="2010-03-05" name="CVE-2010-0930" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0931" published="2010-03-05" name="CVE-2010-0931" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0932" published="2010-03-05" name="CVE-2010-0932" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0933" published="2010-03-05" name="CVE-2010-0933" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:C/A:N)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0934" published="2010-03-05" name="CVE-2010-0934" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" command in conjunction with the form-in trigger script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2008.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0935" published="2010-03-05" name="CVE-2010-0935" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36261" source="BID">36261</ref>
      <ref url="http://www.perforce.com/perforce/doc.current/manuals/cmdref/protect.html" source="CONFIRM">http://www.perforce.com/perforce/doc.current/manuals/cmdref/protect.html</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-March/006063.html" source="MLIST">[dailydave] 20100304 Perforce</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perforce" name="perforce_server">
        <vers num="2000.1" />
        <vers num="2000.2" />
        <vers num="2001.1" />
        <vers num="2001.2" />
        <vers num="2002.1" />
        <vers num="2002.2" />
        <vers num="2003.1" />
        <vers num="2003.2" />
        <vers num="2004.2" />
        <vers num="2005.1" />
        <vers num="2005.2" />
        <vers num="2006.1" />
        <vers num="2006.2" />
        <vers num="2007.2" />
        <vers num="2007.3" />
        <vers num="2007.3_143793" />
        <vers num="2008.1" />
        <vers num="2008.2" />
        <vers prev="1" num="2009.2" />
        <vers num="97.3" />
        <vers num="98.2" />
        <vers num="99.1" />
        <vers num="99.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0936" published="2010-03-08" name="CVE-2010-0936" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55429" source="XF">dkvmip8-auth-xss(55429)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0083" source="VUPEN" adv="1">ADV-2010-0083</ref>
      <ref url="http://www.securityfocus.com/bid/37646" source="BID">37646</ref>
      <ref url="http://www.exploit-db.com/exploits/11030" source="EXPLOIT-DB">11030</ref>
      <ref url="http://secunia.com/advisories/38051" source="SECUNIA" adv="1">38051</ref>
      <ref url="http://osvdb.org/61615" source="OSVDB">61615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d-link" name="dkvm-ip8">
        <vers num="2282_dlinka4_p8_20071213" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0937" published="2010-03-08" name="CVE-2010-0937" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Visualization Library before 2009.08.812 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55478" source="XF">visualizationlibrary-multiple-unspecified(55478)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0050" source="VUPEN" adv="1">ADV-2010-0050</ref>
      <ref url="http://www.securityfocus.com/bid/37644" source="BID">37644</ref>
      <ref url="http://visualizationlibrary.com/documentation/pagchangelog.html" source="CONFIRM">http://visualizationlibrary.com/documentation/pagchangelog.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualizationlibrary" name="visualization_library">
        <vers num="2009.07.640" />
        <vers num="2009.08.800" />
        <vers num="2009.08.802" />
        <vers prev="1" num="2009.08.804" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0938" published="2010-03-08" name="CVE-2010-0938" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55502" source="XF">todooforum-todooforum-xss(55502)</ref>
      <ref url="http://www.exploit-db.com/exploits/11099" source="EXPLOIT-DB">11099</ref>
      <ref url="http://secunia.com/advisories/38060" source="SECUNIA" adv="1">38060</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/todooforum-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/todooforum-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todoomasters" name="todoo_forum">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0939" published="2010-03-08" name="CVE-2010-0939" modified="2010-03-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55505" source="XF">abb-abb-info-disclosure(55505)</ref>
      <ref url="http://www.exploit-db.com/exploits/11096" source="EXPLOIT-DB">11096</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/abbforums-dislclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/abbforums-dislclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visialis" name="abb_forum">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0940" published="2010-03-08" name="CVE-2010-0940" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55522" source="XF">simplephpguestbook-guestbook-xss(55522)</ref>
      <ref url="http://www.exploit-db.com/exploits/11077" source="EXPLOIT-DB">11077</ref>
      <ref url="http://secunia.com/advisories/38053" source="SECUNIA" adv="1">38053</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/simplephpgb-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/simplephpgb-xss.txt</ref>
      <ref url="http://osvdb.org/61614" source="OSVDB">61614</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sanusart" name="simple_php_guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0941" published="2010-03-08" name="CVE-2010-0941" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems Hit Counter 2.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3) admin/index.php, and (4) admin/forgot.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55285" source="XF">hitcounter-index-xss(55285)</ref>
      <ref url="http://www.osvdb.org/61444" source="OSVDB">61444</ref>
      <ref url="http://www.osvdb.org/61443" source="OSVDB">61443</ref>
      <ref url="http://www.osvdb.org/61442" source="OSVDB">61442</ref>
      <ref url="http://www.exploit-db.com/exploits/10887" source="EXPLOIT-DB">10887</ref>
      <ref url="http://secunia.com/advisories/38052" source="SECUNIA" adv="1">38052</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/hitcounter-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/hitcounter-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-site-development" name="etek_systems_hit_counter">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0942" published="2010-03-08" name="CVE-2010-0942" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55513" source="XF">jvideodirect-index-directory-traversal(55513)</ref>
      <ref url="http://www.securityfocus.com/bid/37694" source="BID">37694</ref>
      <ref url="http://www.exploit-db.com/exploits/11089" source="EXPLOIT-DB">11089</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajvideodirect-traversal.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajvideodirect-traversal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jvideodirect" name="com_jvideodirect">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0943" published="2010-03-08" name="CVE-2010-0943" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55512" source="XF">jashowcase-index-directory-traversal(55512)</ref>
      <ref url="http://www.securityfocus.com/bid/37692" source="BID">37692</ref>
      <ref url="http://www.exploit-db.com/exploits/11090" source="EXPLOIT-DB">11090</ref>
      <ref url="http://secunia.com/advisories/33486" source="SECUNIA" adv="1">33486</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajashowcase-traversal.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajashowcase-traversal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlart" name="com_jashowcase">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0944" published="2010-03-08" name="CVE-2010-0944" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55514" source="XF">jcollection-index-directory-traversal(55514)</ref>
      <ref url="http://www.securityfocus.com/bid/37691" source="BID">37691</ref>
      <ref url="http://www.exploit-db.com/exploits/11088" source="EXPLOIT-DB">11088</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajcollection-traversal.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajcollection-traversal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thorsten_riess" name="com_jcollection">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0945" published="2010-03-08" name="CVE-2010-0945" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/54986" source="XF">hotbrackets-id-sql-injection(54986)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0021" source="VUPEN" adv="1">ADV-2010-0021</ref>
      <ref url="http://www.securityfocus.com/bid/37439" source="BID">37439</ref>
      <ref url="http://www.packetstormsecurity.org/0912-exploits/joomlahotbrackets-sql.txt" source="MISC">http://www.packetstormsecurity.org/0912-exploits/joomlahotbrackets-sql.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/10953" source="EXPLOIT-DB">10953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hotbrackets" name="com_hotbrackets">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0946" published="2010-03-08" name="CVE-2010-0946" modified="2010-03-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55526" source="XF">kisssoftware-index-sql-injection(55526)</ref>
      <ref url="http://www.securityfocus.com/bid/37682" source="BID">37682</ref>
      <ref url="http://explo.it/exploits/11068" source="MISC">http://explo.it/exploits/11068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kiss-software" name="com_ksadvertiser">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0947" published="2010-03-10" name="CVE-2010-0947" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.aspx in Max Network Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38592" source="BID">38592</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509905/100/0/threaded" source="BUGTRAQ">20100306 [xss] a xss on "action" parameter in BBSMAX</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/bbsmax-xss.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/bbsmax-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbsmax" name="bbsmax">
        <vers num="3.0" />
        <vers num="4.1" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0948" published="2010-03-10" name="CVE-2010-0948" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56723" source="XF">bigforum-profil-sql-injection(56723)</ref>
      <ref url="http://www.securityfocus.com/bid/38597" source="BID">38597</ref>
      <ref url="http://www.exploit-db.com/exploits/11646" source="EXPLOIT-DB">11646</ref>
      <ref url="http://secunia.com/advisories/38872" source="SECUNIA" adv="1">38872</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/bigforum-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/bigforum-sql.txt</ref>
      <ref url="http://osvdb.org/62778" source="OSVDB">62778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bfs.kilu" name="bigforum">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0949" published="2010-03-10" name="CVE-2010-0949" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Natychmiast CMS allow remote attackers to inject arbitrary web script or HTML via the id_str parameter to (1) index.php and (2) a_index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56724" source="XF">natychmiast-index-xss(56724)</ref>
      <ref url="http://www.securityfocus.com/bid/38561" source="BID">38561</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509890/100/0/threaded" source="BUGTRAQ">20100305 SQL injection vulnerability in Natychmiast CMS</ref>
      <ref url="http://www.packetstormsecurity.com/1003-exploits/natychmiast-sqlxss.txt" source="MISC">http://www.packetstormsecurity.com/1003-exploits/natychmiast-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="natychmiast-cms" name="natychmiast-cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0950" published="2010-03-10" name="CVE-2010-0950" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Natychmiast CMS allow remote attackers to execute arbitrary SQL commands via the id_str parameter to (1) index.php and (2) a_index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56725" source="XF">natychmiast-index-sql-injection(56725)</ref>
      <ref url="http://www.securityfocus.com/bid/38561" source="BID">38561</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509890/100/0/threaded" source="BUGTRAQ">20100305 SQL injection vulnerability in Natychmiast CMS</ref>
      <ref url="http://www.packetstormsecurity.com/1003-exploits/natychmiast-sqlxss.txt" source="MISC">http://www.packetstormsecurity.com/1003-exploits/natychmiast-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="natychmiast-cms" name="natychmiast-cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0951" published="2010-03-10" name="CVE-2010-0951" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56722" source="XF">dev4ucms-gotarget-sql-injection(56722)</ref>
      <ref url="http://www.securityfocus.com/bid/38577" source="BID">38577</ref>
      <ref url="http://www.exploit-db.com/exploits/11643" source="EXPLOIT-DB">11643</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/dev4u-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/dev4u-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev4u" name="dev4u_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0952" published="2010-03-10" name="CVE-2010-0952" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56700" source="XF">onecms-index-sql-injection(56700)</ref>
      <ref url="http://www.securityfocus.com/bid/38557" source="BID">38557</ref>
      <ref url="http://www.exploit-db.com/exploits/11635" source="EXPLOIT-DB">11635</ref>
      <ref url="http://secunia.com/advisories/30378" source="SECUNIA" adv="1">30378</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/onecmsv25-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/onecmsv25-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insanevisions" name="onecms">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0953" published="2010-03-10" name="CVE-2010-0953" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56721" source="XF">phpcoin-mod-file-include(56721)</ref>
      <ref url="http://www.securityfocus.com/bid/38576" source="BID">38576</ref>
      <ref url="http://www.exploit-db.com/exploits/11641" source="EXPLOIT-DB">11641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcoin" name="phpcoin">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0954" published="2010-03-10" name="CVE-2010-0954" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56729" source="XF">preelearning-searchresult-sql-injection(56729)</ref>
      <ref url="http://www.securityfocus.com/bid/38582" source="BID">38582</ref>
      <ref url="http://www.packetstormsecurity.com/1003-exploits/preelearningportal-sql.txt" source="MISC">http://www.packetstormsecurity.com/1003-exploits/preelearningportal-sql.txt</ref>
      <ref url="http://secunia.com/advisories/38891" source="SECUNIA" adv="1">38891</ref>
      <ref url="http://osvdb.org/62774" source="OSVDB">62774</ref>
      <ref url="http://evilc0de.blogspot.com/2010/03/pre-e-learning-portal-sql-injection.html" source="MISC">http://evilc0de.blogspot.com/2010/03/pre-e-learning-portal-sql-injection.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="preprojects" name="pre_e-learning_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0955" published="2010-03-10" name="CVE-2010-0955" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56727" source="XF">bildflirt-index-sql-injection(56727)</ref>
      <ref url="http://www.securityfocus.com/bid/38585" source="BID">38585</ref>
      <ref url="http://www.exploit-db.com/exploits/11648" source="EXPLOIT-DB">11648</ref>
      <ref url="http://secunia.com/advisories/38870" source="SECUNIA" adv="1">38870</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/bildflirt-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/bildflirt-sql.txt</ref>
      <ref url="http://osvdb.org/62780" source="OSVDB">62780</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/07/bild-flirt-system-v2-0-index-php-id-sql-injection/" source="MISC">http://4004securityproject.wordpress.com/2010/03/07/bild-flirt-system-v2-0-index-php-id-sql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="media-products" name="bild_flirt_community">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0956" published="2010-03-10" name="CVE-2010-0956" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38605" source="BID">38605</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/opencart-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/opencart-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opencart" name="opencart">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0957" published="2010-03-10" name="CVE-2010-0957" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56358" source="XF">shopsystem-content-file-include(56358)</ref>
      <ref url="http://www.securityfocus.com/bid/38574" source="BID">38574</ref>
      <ref url="http://www.exploit-db.com/exploits/11433" source="EXPLOIT-DB">11433</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/saskiashopsystem-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/saskiashopsystem-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saskia_bruckner" name="saskias_shopsystem">
        <vers prev="1" num="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0958" published="2010-03-10" name="CVE-2010-0958" modified="2010-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38596" source="BID">38596</ref>
      <ref url="http://www.exploit-db.com/exploits/11655" source="EXPLOIT-DB">11655</ref>
      <ref url="http://secunia.com/advisories/28362" source="SECUNIA" adv="1">28362</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/tribisur-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/tribisur-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thomas_perez" name="tribisur">
        <vers num="2.0" />
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0959" published="2010-03-10" name="CVE-2010-0959" modified="2010-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38612" source="BID">38612</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509975/100/0/threaded" source="BUGTRAQ">20100309 IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability</ref>
      <ref url="http://osvdb.org/62901" source="OSVDB">62901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="enovia_smarteam">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0960" published="2010-03-10" name="CVE-2010-0960" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0557" source="VUPEN" adv="1">ADV-2010-0557</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71870" source="AIXAPAR">IZ71870</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71627" source="AIXAPAR">IZ71627</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71555" source="AIXAPAR">IZ71555</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ68231" source="AIXAPAR">IZ68231</ref>
      <ref url="http://securitytracker.com/id?1023695" source="SECTRACK">1023695</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6822" source="OVAL">oval:org.mitre.oval:def:6822</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/qosmod_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/qosmod_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="vios">
        <vers num="2.1" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="6.1" />
        <vers num="6.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0961" published="2010-03-10" name="CVE-2010-0961" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0556" source="VUPEN" adv="1">ADV-2010-0556</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71869" source="AIXAPAR" adv="1">IZ71869</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71590" source="AIXAPAR" adv="1">IZ71590</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ71554" source="AIXAPAR" adv="1">IZ71554</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ68194" source="AIXAPAR" adv="1">IZ68194</ref>
      <ref url="http://securitytracker.com/id?1023694" source="SECTRACK">1023694</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12051" source="OVAL">oval:org.mitre.oval:def:12051</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/qoslist_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/qoslist_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="vios">
        <vers num="2.1" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="6.1" />
        <vers num="6.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0962" published="2010-03-10" name="CVE-2010-0962" modified="2010-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56701" source="XF">apple-ftpproxy-security-bypass(56701)</ref>
      <ref url="http://www.securityfocus.com/bid/38543" source="BID">38543</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509974/100/0/threaded" source="BUGTRAQ">20100309 Re: Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509867/100/0/threaded" source="BUGTRAQ">20100304 Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Mar/106" source="FULLDISC">20100304 Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_express">
        <vers num="7.5" />
      </prod>
      <prod vendor="apple" name="airport_extreme">
        <vers num="7.5" />
      </prod>
      <prod vendor="apple" name="time_capsule">
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0963" published="2010-03-16" name="CVE-2010-0963" modified="2010-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38700" source="BID" patch="1">38700</ref>
      <ref url="http://freshmeat.net/projects/dl-ticket-service" source="CONFIRM" patch="1">http://freshmeat.net/projects/dl-ticket-service</ref>
      <ref url="http://article.gmane.org/gmane.comp.web.dl-ticket-service.general/33" source="MLIST" patch="1">[dl-ticket-service] 20100311 dl 0.7 released</ref>
      <ref url="http://secunia.com/advisories/38898" source="SECUNIA" adv="1">38898</ref>
      <ref url="http://osvdb.org/62884" source="OSVDB">62884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yuri_d'elia" name="dl">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers prev="1" num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0964" published="2010-03-16" name="CVE-2010-0964" modified="2010-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in start.php in Eros Webkatalog allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56851" source="XF">eroswebkatalog-start-sql-injection(56851)</ref>
      <ref url="http://www.exploit-db.com/exploits/11689" source="EXPLOIT-DB">11689</ref>
      <ref url="http://secunia.com/advisories/38900" source="SECUNIA" adv="1">38900</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/eroserotikwebkat-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/eroserotikwebkat-sql.txt</ref>
      <ref url="http://osvdb.org/62902" source="OSVDB">62902</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/11/eros-erotik-webkatalog-start-php-rubrikidsql-injection/" source="MISC">http://4004securityproject.wordpress.com/2010/03/11/eros-erotik-webkatalog-start-php-rubrikidsql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="media-products" name="eros_webkatalog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0965" published="2010-03-16" name="CVE-2010-0965" modified="2010-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Jevci Siparis Formu Scripti stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for siparis.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56794" source="XF">jevci-siparis-information-disclosure(56794)</ref>
      <ref url="http://secunia.com/advisories/38893" source="SECUNIA" adv="1">38893</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/jevci-disclose.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/jevci-disclose.txt</ref>
      <ref url="http://osvdb.org/62843" source="OSVDB">62843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jevci.net" name="jevci_siparis_formu_scripti">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0966" published="2010-03-16" name="CVE-2010-0966" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0615" source="VUPEN" adv="1">ADV-2010-0615</ref>
      <ref url="http://www.exploit-db.com/exploits/11735" source="EXPLOIT-DB">11735</ref>
      <ref url="http://secunia.com/advisories/38902" source="SECUNIA" adv="1">38902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dzcp" name="dev!l'z_clanportal">
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0967" published="2010-03-16" name="CVE-2010-0967" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php in themes/.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56857" source="XF">geekhelpsadmp-style-file-include(56857)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0612" source="VUPEN" adv="1">ADV-2010-0612</ref>
      <ref url="http://www.exploit-db.com/exploits/11721" source="EXPLOIT-DB">11721</ref>
      <ref url="http://secunia.com/advisories/38949" source="SECUNIA" adv="1">38949</ref>
      <ref url="http://osvdb.org/62918" source="OSVDB">62918</ref>
      <ref url="http://osvdb.org/62917" source="OSVDB">62917</ref>
      <ref url="http://osvdb.org/62916" source="OSVDB">62916</ref>
      <ref url="http://osvdb.org/62915" source="OSVDB">62915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geekhelps" name="admp">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0968" published="2010-03-16" name="CVE-2010-0968" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0612" source="VUPEN" adv="1">ADV-2010-0612</ref>
      <ref url="http://www.exploit-db.com/exploits/11721" source="EXPLOIT-DB">11721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geekhelps" name="admp">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0969" published="2010-03-16" name="CVE-2010-0969" modified="2011-06-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.unbound.net/pipermail/unbound-users/2010-March/001057.html" source="MLIST" patch="1">[unbound-users] 20100311 Unbound 1.4.3 release</ref>
      <ref url="http://www.securityfocus.com/bid/38701" source="BID" patch="1">38701</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/12/3" source="MLIST">[oss-security] 20100312 CVE Request -- Unbound v1.4.3 -- 64 bit platforms specific remote DoS</ref>
      <ref url="http://secunia.com/advisories/38888" source="SECUNIA" adv="1">38888</ref>
      <ref url="http://osvdb.org/62903" source="OSVDB">62903</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=126876222231747&amp;w=2" source="MLIST">[oss-security] 20100316 Re: CVE Request -- Unbound v1.4.3 -- 64 bit platforms specific remote DoS</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=309117" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=309117</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nlnetlabs" name="unbound">
        <vers num="0.0" />
        <vers num="0.09" />
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers prev="1" num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0970" published="2010-03-16" name="CVE-2010-0970" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56868" source="XF">phpmylogon-phpmylogon-sql-injection(56868)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0614" source="VUPEN" adv="1">ADV-2010-0614</ref>
      <ref url="http://www.exploit-db.com/exploits/11737" source="EXPLOIT-DB">11737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jorik_berkepas" name="phpmylogon">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0971" published="2010-03-16" name="CVE-2010-0971" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56852" source="XF">atutor-add-xss(56852)</ref>
      <ref url="http://www.securityfocus.com/bid/38656" source="BID">38656</ref>
      <ref url="http://www.exploit-db.com/exploits/11685" source="EXPLOIT-DB">11685</ref>
      <ref url="http://secunia.com/advisories/38906" source="SECUNIA" adv="1">38906</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/atutor-xss.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/atutor-xss.txt</ref>
      <ref url="http://osvdb.org/62906" source="OSVDB">62906</ref>
      <ref url="http://osvdb.org/62905" source="OSVDB">62905</ref>
      <ref url="http://osvdb.org/62904" source="OSVDB">62904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atutor" name="atutor">
        <vers num="1.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0972" published="2010-03-16" name="CVE-2010-0972" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56863" source="XF">gcalendar-index-file-include(56863)</ref>
      <ref url="http://www.exploit-db.com/exploits/11738" source="EXPLOIT-DB">11738</ref>
      <ref url="http://secunia.com/advisories/38925" source="SECUNIA" adv="1">38925</ref>
    </refs>
    <vuln_soft>
      <prod vendor="g4j.laoneo" name="com_gcalendar">
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0973" published="2010-03-16" name="CVE-2010-0973" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56872" source="XF">verkaus-index-sql-injection(56872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0616" source="VUPEN" adv="1">ADV-2010-0616</ref>
      <ref url="http://www.exploit-db.com/exploits/11733" source="EXPLOIT-DB">11733</ref>
      <ref url="http://secunia.com/advisories/38939" source="SECUNIA" adv="1">38939</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/14/phppool-media-domain-verkaufs-und-auktions-portal-index-php-sql-injection/" source="MISC">http://4004securityproject.wordpress.com/2010/03/14/phppool-media-domain-verkaufs-und-auktions-portal-index-php-sql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scripteverkauf" name="domain_verkaus_and_auktions_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0974" published="2010-03-16" name="CVE-2010-0974" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56811" source="XF">phpcityportal-id-sql-injection(56811)</ref>
      <ref url="http://www.securityfocus.com/bid/38649" source="BID">38649</ref>
      <ref url="http://www.packetstormsecurity.com/1003-exploits/phpcityportal-sqlrfi.txt" source="MISC">http://www.packetstormsecurity.com/1003-exploits/phpcityportal-sqlrfi.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/11678" source="EXPLOIT-DB">11678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcityportal" name="phpcityportal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0975" published="2010-03-16" name="CVE-2010-0975" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56812" source="XF">phpcityportal-external-file-include(56812)</ref>
      <ref url="http://www.exploit-db.com/exploits/11678" source="EXPLOIT-DB">11678</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/phpcityportal-sqlrfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/phpcityportal-sqlrfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcityportal" name="phpcityportal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0976" published="2010-03-16" name="CVE-2010-0976" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts.  NOTE: the final installation screen states "Important: you must now delete all files beginning with 'install' from the root directory."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55331" source="XF">acidcat-install-info-disclosure(55331)</ref>
      <ref url="http://www.exploit-db.com/exploits/10972" source="EXPLOIT-DB">10972</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acidcat" name="acidcat_cms">
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0977" published="2010-03-16" name="CVE-2010-0977" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/10995" source="EXPLOIT-DB">10995</ref>
      <ref url="http://secunia.com/advisories/38109" source="SECUNIA" adv="1">38109</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/pdportal-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/pdportal-disclose.txt</ref>
      <ref url="http://osvdb.org/61468" source="OSVDB">61468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pordus" name="pd_portal">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0978" published="2010-03-16" name="CVE-2010-0978" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55376" source="XF">kmsoft-guestbok-db-info-disclosure(55376)</ref>
      <ref url="http://www.exploit-db.com/exploits/11005" source="EXPLOIT-DB">11005</ref>
      <ref url="http://secunia.com/advisories/38076" source="SECUNIA" adv="1">38076</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/kmsoftgb-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/kmsoftgb-disclose.txt</ref>
      <ref url="http://osvdb.org/61487" source="OSVDB">61487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kmsoft" name="guestbook">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0979" published="2010-03-16" name="CVE-2010-0979" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0048" source="VUPEN" adv="1">ADV-2010-0048</ref>
      <ref url="http://secunia.com/advisories/38107" source="SECUNIA" adv="1">38107</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/odig-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/odig-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="obsession-design" name="image-gallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0980" published="2010-03-16" name="CVE-2010-0980" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55299" source="XF">left4deadstats-player-sql-injection(55299)</ref>
      <ref url="http://www.exploit-db.com/exploits/10930" source="EXPLOIT-DB">10930</ref>
      <ref url="http://secunia.com/advisories/38008" source="SECUNIA" adv="1">38008</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/left4deadstats-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/left4deadstats-sql.txt</ref>
      <ref url="http://osvdb.org/61472" source="OSVDB">61472</ref>
      <ref url="http://greyhathackers.wordpress.com/2010/01/02/left-4-dead-stats-1-1-sql-injection-vulnerability/" source="MISC">http://greyhathackers.wordpress.com/2010/01/02/left-4-dead-stats-1-1-sql-injection-vulnerability/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mitchell_sleeper" name="l4d_stats">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0981" published="2010-03-16" name="CVE-2010-0981" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55350" source="XF">tpjobs-idc-sql-injection(55350)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0023" source="VUPEN" adv="1">ADV-2010-0023</ref>
      <ref url="http://www.securityfocus.com/bid/37591" source="BID">37591</ref>
      <ref url="http://www.exploit-db.com/exploits/10950" source="EXPLOIT-DB">10950</ref>
      <ref url="http://secunia.com/advisories/38001" source="SECUNIA" adv="1">38001</ref>
      <ref url="http://packetstormsecurity.org/0912-exploits/joomlatpjobs-sql.txt" source="MISC">http://packetstormsecurity.org/0912-exploits/joomlatpjobs-sql.txt</ref>
      <ref url="http://osvdb.org/61477" source="OSVDB">61477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="templateplazza" name="com_tpjobs">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0982" published="2010-03-16" name="CVE-2010-0982" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37581" source="BID">37581</ref>
      <ref url="http://secunia.com/advisories/37917" source="SECUNIA" adv="1">37917</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlacartweberp-lfi.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlacartweberp-lfi.txt</ref>
      <ref url="http://osvdb.org/61447" source="OSVDB">61447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlamo" name="com_cartweberp">
        <vers num="1.56.75" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0983" published="2010-03-16" name="CVE-2010-0983" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root parameter, a different vector than CVE-2007-2156.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55341" source="XF">rezervi-mailinc-file-include(55341)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0016" source="VUPEN" adv="1">ADV-2010-0016</ref>
      <ref url="http://www.securityfocus.com/bid/37589" source="BID">37589</ref>
      <ref url="http://www.exploit-db.com/exploits/10967" source="EXPLOIT-DB">10967</ref>
      <ref url="http://secunia.com/advisories/38118" source="SECUNIA" adv="1">38118</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/rezervi-rfi.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/rezervi-rfi.txt</ref>
      <ref url="http://osvdb.org/61450" source="OSVDB">61450</ref>
    </refs>
    <vuln_soft>
      <prod vendor="utilo" name="rezervi">
        <vers prev="1" num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0984" published="2010-03-16" name="CVE-2010-0984" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55329" source="XF">acidcat-acidcat3-info-disclosure(55329)</ref>
      <ref url="http://www.exploit-db.com/exploits/10972" source="EXPLOIT-DB">10972</ref>
      <ref url="http://secunia.com/advisories/38084" source="SECUNIA" adv="1">38084</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/acidcatcms-disclose.txt</ref>
      <ref url="http://osvdb.org/61436" source="OSVDB">61436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acidcat" name="acidcat_cms">
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="3.3.5" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers prev="1" num="3.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0985" published="2010-03-16" name="CVE-2010-0985" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55348" source="XF">abbreviations-index-file-include(55348)</ref>
      <ref url="http://www.securityfocus.com/bid/37560" source="BID">37560</ref>
      <ref url="http://www.exploit-db.com/exploits/10948" source="EXPLOIT-DB">10948</ref>
      <ref url="http://secunia.com/advisories/37834" source="SECUNIA" adv="1">37834</ref>
      <ref url="http://osvdb.org/61458" source="OSVDB">61458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chris_simon" name="com_abbrev">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0986" published="2010-05-13" name="CVE-2010-0986" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40086" source="BID">40086</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511264/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player Asset Entry Parsing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-34/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-34/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6967" source="OVAL">oval:org.mitre.oval:def:6967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0987" published="2010-05-13" name="CVE-2010-0987" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40093" source="BID">40093</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511265/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: Adobe Shockwave Player Font Processing Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2010-50/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-50/</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7052" source="OVAL">oval:org.mitre.oval:def:7052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0988" published="2010-03-26" name="CVE-2010-0988" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to arbitrary files and execute arbitrary PHP code via vectors involving the (2) filename and (3) block parameters to view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38956" source="BID">38956</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510300/100/0/threaded" source="BUGTRAQ">20100324 Secunia Research: Pulse CMS login.php Arbitrary File Writing Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510299/100/0/threaded" source="BUGTRAQ">20100324 Secunia Research: Pulse CMS Arbitrary File Writing Vulnerability</ref>
      <ref url="http://www.osvdb.org/63168" source="OSVDB">63168</ref>
      <ref url="http://www.osvdb.org/63166" source="OSVDB">63166</ref>
      <ref url="http://secunia.com/secunia_research/2010-51/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-51/</ref>
      <ref url="http://secunia.com/secunia_research/2010-45/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-45/</ref>
      <ref url="http://secunia.com/advisories/39011" source="SECUNIA" adv="1">39011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.0" edition="-" />
        <vers num="1.01" />
        <vers num="1.1" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0989" published="2010-03-26" name="CVE-2010-0989" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38947" source="BID">38947</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510307/100/0/threaded" source="BUGTRAQ">20100324 Secunia Research: Pulse CMS Arbitrary File Deletion Vulnerability</ref>
      <ref url="http://www.osvdb.org/63167" source="OSVDB">63167</ref>
      <ref url="http://secunia.com/secunia_research/2010-48/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-48/</ref>
      <ref url="http://secunia.com/advisories/39011" source="SECUNIA" adv="1">39011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.0" edition="-" />
        <vers num="1.01" />
        <vers num="1.1" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers num="1.17" />
        <vers num="1.18" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0990" published="2010-06-15" name="CVE-2010-0990" modified="2010-06-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40768" source="BID">40768</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511795/100/0/threaded" source="BUGTRAQ">20100611 Secunia Research: Creative Software AutoUpdate Engine 2 ActiveX Control Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2010-52/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-52/</ref>
      <ref url="http://secunia.com/advisories/38970" source="SECUNIA" adv="1">38970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="creative" name="autoupdate">
        <vers num="1.40.01" />
      </prod>
      <prod vendor="creative" name="autoupdate_engine_activex_control">
        <vers num="2.0.12.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0991" published="2010-04-22" name="CVE-2010-0991" modified="2010-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafted (1) ARGB, (2) XPM, or (3) BMP file, related to the IMAGE_DIMENSIONS_OK macro in lib/image.h.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0959" source="VUPEN" adv="1">ADV-2010-0959</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510866/100/0/threaded" source="BUGTRAQ">20100421 Secunia Research: imlib2 "IMAGE_DIMENSIONS_OK()" Logic Error</ref>
      <ref url="http://secunia.com/secunia_research/2010-54/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-54/</ref>
      <ref url="http://secunia.com/advisories/39354" source="SECUNIA" adv="1">39354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enlightenment" name="imlib2">
        <vers num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0992" published="2010-04-09" name="CVE-2010-0992" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote attackers to hijack the authentication of users for requests that (1) upload image files, (2) delete image files, or (3) create blocks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://pulsecms.com/blog.php" source="CONFIRM" patch="1" adv="1">http://pulsecms.com/blog.php</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510619/100/0/threaded" source="BUGTRAQ">20100409 Secunia Research: Pulse CMS Cross-Site Request Forgery</ref>
      <ref url="http://secunia.com/secunia_research/2010-46/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-46/</ref>
      <ref url="http://secunia.com/advisories/39046" source="SECUNIA" adv="1">39046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.2.2" edition="-" />
        <vers num="1.2.2" edition="-:basic" />
        <vers num="1.2.3" edition="-" />
        <vers num="1.2.3" edition="-:basic" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0993" published="2010-04-09" name="CVE-2010-0993" modified="2010-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html

'Unrestricted Upload of File with Dangerous Type'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pulsecms.com/blog.php" source="CONFIRM" patch="1" adv="1">http://pulsecms.com/blog.php</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510617/100/0/threaded" source="BUGTRAQ">20100409 Secunia Research: Pulse CMS Arbitrary File Upload Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-47/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-47/</ref>
      <ref url="http://secunia.com/advisories/39046" source="SECUNIA" adv="1">39046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.2.2" edition="-" />
        <vers num="1.2.2" edition="-:basic" />
        <vers num="1.2.3" edition="-" />
        <vers num="1.2.3" edition="-:basic" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0994" published="2010-04-15" name="CVE-2010-0994" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in src/vl/vlDAT.cpp in Visualization Library 2009.08.812 allow user-assisted remote attackers to execute arbitrary code via a crafted DAT file, related to the (1) vl::loadDAT and (2) vl::isDAT functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39471" source="BID">39471</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510710/100/0/threaded" source="BUGTRAQ">20100414 Secunia Research: Visualization Library DAT File Parsing Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-02/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-02/</ref>
      <ref url="http://secunia.com/advisories/38162" source="SECUNIA" adv="1">38162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="visualizationlibrary" name="visualization_library">
        <vers num="2009.08.812" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0995" published="2010-05-06" name="CVE-2010-0995" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39822" source="BID">39822</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511060/100/0/threaded" source="BUGTRAQ">20100430 Secunia Research: Internet Download Manager FTP Buffer Overflow Vulnerability</ref>
      <ref url="http://www.internetdownloadmanager.com/news.html" source="MISC">http://www.internetdownloadmanager.com/news.html</ref>
      <ref url="http://secunia.com/secunia_research/2010-62/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-62/</ref>
      <ref url="http://secunia.com/advisories/39446" source="SECUNIA" adv="1">39446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tonec" name="internet_download_manager">
        <vers prev="1" num="5.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-0996" published="2010-04-20" name="CVE-2010-0996" modified="2010-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in e107 before 0.7.20 allows remote authenticated users to execute arbitrary code by uploading a .php.filetypesphp file.  NOTE: the vendor disputes the significance of this issue, noting that "an odd set of preferences and a missing file" are required.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html

'CWE-434: Unrestricted Upload of File with Dangerous Type'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://e107.org/comment.php?comment.news.864" source="CONFIRM" patch="1" adv="1">http://e107.org/comment.php?comment.news.864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57932" source="XF">e107-phpfiletypesphp-file-upload(57932)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0919" source="VUPEN" adv="1">ADV-2010-0919</ref>
      <ref url="http://www.securityfocus.com/bid/39540" source="BID">39540</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510805/100/0/threaded" source="BUGTRAQ">20100419 Secunia Research: e107 Avatar/Photograph Image File Upload Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-44/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-44/</ref>
      <ref url="http://secunia.com/advisories/39013" source="SECUNIA" adv="1">39013</ref>
      <ref url="http://e107.org/svn_changelog.php?version=0.7.20" source="MISC">http://e107.org/svn_changelog.php?version=0.7.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.547" edition="beta" />
        <vers num="0.548" edition="beta" />
        <vers num="0.549" edition="beta" />
        <vers num="0.551" edition="beta" />
        <vers num="0.552" edition="beta" />
        <vers num="0.553" edition="beta" />
        <vers num="0.554" edition="beta" />
        <vers num="0.555" edition="beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="0.6171" />
        <vers num="0.6172" />
        <vers num="0.6173" />
        <vers num="0.6174" />
        <vers num="0.6175" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.12" />
        <vers num="0.7.13" />
        <vers num="0.7.14" />
        <vers num="0.7.15" />
        <vers num="0.7.16" />
        <vers num="0.7.17" />
        <vers num="0.7.18" />
        <vers prev="1" num="0.7.19" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.1" />
        <vers num="5.21" />
        <vers num="5.3" edition="beta" />
        <vers num="5.3" edition="beta2" />
        <vers num="5.4" edition="beta1" />
        <vers num="5.4" edition="beta2" />
        <vers num="5.4" edition="beta3" />
        <vers num="5.4" edition="beta4" />
        <vers num="5.4" edition="beta5" />
        <vers num="5.4" edition="beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-0997" published="2010-04-20" name="CVE-2010-0997" modified="2010-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in 107_plugins/content/content_manager.php in the Content Management plugin in e107 before 0.7.20, when the personal content manager is enabled, allows user-assisted remote authenticated users to inject arbitrary web script or HTML via the content_heading parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://e107.org/comment.php?comment.news.864" source="CONFIRM" patch="1">http://e107.org/comment.php?comment.news.864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57933" source="XF">e107-contentmanager-xss(57933)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0919" source="VUPEN" adv="1">ADV-2010-0919</ref>
      <ref url="http://www.securityfocus.com/bid/39539" source="BID">39539</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510809/100/0/threaded" source="BUGTRAQ">20100419 Secunia Research: e107 Content Management Plugin Script Insertion Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-43/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-43/</ref>
      <ref url="http://secunia.com/advisories/39013" source="SECUNIA" adv="1">39013</ref>
      <ref url="http://e107.org/svn_changelog.php?version=0.7.20" source="MISC">http://e107.org/svn_changelog.php?version=0.7.20</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.12" />
        <vers num="0.7.13" />
        <vers num="0.7.14" />
        <vers num="0.7.15" />
        <vers num="0.7.16" />
        <vers num="0.7.17" />
        <vers num="0.7.18" />
        <vers prev="1" num="0.7.19" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0998" published="2010-05-17" name="CVE-2010-0998" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58626" source="XF">fdm-siteexplorer-bo(58626)</ref>
      <ref url="http://www.securityfocus.com/bid/40146" source="BID">40146</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511282/100/0/threaded" source="BUGTRAQ">20100513 Secunia Research: Free Download Manager Four Buffer Overflow Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-68/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-68/</ref>
      <ref url="http://secunia.com/advisories/39447" source="SECUNIA" adv="1">39447</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7006" source="OVAL">oval:org.mitre.oval:def:7006</ref>
      <ref url="http://osvdb.org/64674" source="OSVDB">64674</ref>
      <ref url="http://osvdb.org/64673" source="OSVDB">64673</ref>
      <ref url="http://osvdb.org/64672" source="OSVDB">64672</ref>
      <ref url="http://osvdb.org/64671" source="OSVDB">64671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedownloadmanager" name="free_download_manager">
        <vers num="2" />
        <vers num="2.1" />
        <vers num="2.5.700" />
        <vers num="2.5.704" />
        <vers num="2.5.724" />
        <vers num="3.0.843" />
        <vers num="3.0.848" />
        <vers num="3.0.850" />
        <vers prev="1" num="3.0.851" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-0999" published="2010-05-17" name="CVE-2010-0999" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58627" source="XF">fdm-name-directory-traversal(58627)</ref>
      <ref url="http://www.securityfocus.com/bid/40152" source="BID">40152</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511284/100/0/threaded" source="BUGTRAQ">20100513 Secunia Research: Free Download Manager metalink "name" Directory Traversal</ref>
      <ref url="http://secunia.com/secunia_research/2010-67/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-67/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7284" source="OVAL">oval:org.mitre.oval:def:7284</ref>
      <ref url="http://osvdb.org/64670" source="OSVDB">64670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedownloadmanager" name="free_download_manager">
        <vers num="2" />
        <vers num="2.1" />
        <vers num="2.5.700" />
        <vers num="2.5.704" />
        <vers num="2.5.724" />
        <vers num="3.0.843" />
        <vers num="3.0.848" />
        <vers num="3.0.850" />
        <vers prev="1" num="3.0.851" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1000" published="2010-05-17" name="CVE-2010-1000" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.kde.org/info/security/advisory-20100513-1.txt

'Patches have been committed to the KDE Subversion repository in the
    following revision numbers:

    4.3 branch: r1126227
    4.4 branch: r1124974
    Trunk: r1124976'
</sol>
    </sols>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58628" source="XF">kde-name-directory-traversal(58628)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/1101" source="VUPEN">ADV-2011-1101</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3096" source="VUPEN" adv="1">ADV-2010-3096</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1144" source="VUPEN" adv="1">ADV-2010-1144</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1142" source="VUPEN" adv="1">ADV-2010-1142</ref>
      <ref url="http://www.ubuntu.com/usn/USN-938-1" source="UBUNTU">USN-938-1</ref>
      <ref url="http://www.securityfocus.com/bid/40141" source="BID">40141</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511294/100/0/threaded" source="BUGTRAQ">20100514 Re: Secunia Research: KDE KGet Insecure File Operation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511281/100/0/threaded" source="BUGTRAQ">20100513 Secunia Research: KDE KGet metalink </ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:098" source="MANDRIVA">MDVSA-2010:098</ref>
      <ref url="http://www.kde.org/info/security/advisory-20100513-1.txt" source="CONFIRM" adv="1">http://www.kde.org/info/security/advisory-20100513-1.txt</ref>
      <ref url="http://securitytracker.com/id?1023984" source="SECTRACK">1023984</ref>
      <ref url="http://secunia.com/secunia_research/2010-69/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-69/</ref>
      <ref url="http://secunia.com/advisories/42423" source="SECUNIA" adv="1">42423</ref>
      <ref url="http://secunia.com/advisories/39787" source="SECUNIA" adv="1">39787</ref>
      <ref url="http://secunia.com/advisories/39528" source="SECUNIA" adv="1">39528</ref>
      <ref url="http://osvdb.org/64690" source="OSVDB">64690</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127378789518426&amp;w=2" source="MLIST">[oss-security] 20100513 KDENetwork vulnerabilities</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058580.html" source="FEDORA">FEDORA-2011-5211</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html" source="FEDORA">FEDORA-2010-18029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde_sc">
        <vers num="4.0.0" edition="alpha1" />
        <vers num="4.0.0" edition="alpha2" />
        <vers num="4.0.0" edition="beta1" />
        <vers num="4.0.0" edition="beta2" />
        <vers num="4.0.0" edition="beta3" />
        <vers num="4.0.0" edition="beta4" />
        <vers num="4.0.0" edition="rc1" />
        <vers num="4.0.0" edition="rc2" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1.0" edition="alpha1" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="beta2" />
        <vers num="4.1.0" edition="rc" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.80" />
        <vers num="4.1.85" />
        <vers num="4.1.96" />
        <vers num="4.2" edition="beta2" />
        <vers num="4.2" edition="rc" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.3.0" edition="beta1" />
        <vers num="4.3.0" edition="beta3" />
        <vers num="4.3.0" edition="rc1" />
        <vers num="4.3.0" edition="rc2" />
        <vers num="4.3.0" edition="rc3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="rc1" />
        <vers num="4.4.0" edition="rc2" />
        <vers num="4.4.0" edition="rc3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1003" published="2010-03-19" name="CVE-2010-1003" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38787" source="BID" patch="1">38787</ref>
      <ref url="http://www.efrontlearning.net/product/efront-news/265-important-security-fix.html" source="CONFIRM" patch="1" adv="1">http://www.efrontlearning.net/product/efront-news/265-important-security-fix.html</ref>
      <ref url="http://www.coresecurity.com/content/efront-php-file-inclusion" source="MISC" patch="1">http://www.coresecurity.com/content/efront-php-file-inclusion</ref>
      <ref url="http://forum.efrontlearning.net/viewtopic.php?f=15&amp;t=1945" source="CONFIRM" patch="1" adv="1">http://forum.efrontlearning.net/viewtopic.php?f=15&amp;t=1945</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510155/100/0/threaded" source="BUGTRAQ">20100316 CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability</ref>
      <ref url="http://osvdb.org/63028" source="OSVDB">63028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efrontlearning" name="efront">
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1004" published="2010-03-19" name="CVE-2010-1004" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Yet another TYPO3 search engine (YATSE) extension before 0.3.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38808" source="BID" patch="1">38808</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/yatse/0.3.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/yatse/0.3.2/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mischa_heimann" name="yatse">
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers prev="1" num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1005" published="2010-03-19" name="CVE-2010-1005" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Yet another TYPO3 search engine (YATSE) extension before 0.3.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38808" source="BID" patch="1">38808</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/yatse/0.3.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/yatse/0.3.2/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mischa_heimann" name="yatse">
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers prev="1" num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1006" published="2010-03-19" name="CVE-2010-1006" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38798" source="BID">38798</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="brainstorming">
        <vers prev="1" num="0.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1007" published="2010-03-19" name="CVE-2010-1007" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38811" source="BID">38811</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chi_hoang" name="ch_lightem">
        <vers prev="1" num="1.0.34" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1008" published="2010-03-19" name="CVE-2010-1008" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Sellector.com Widget Integration (chsellector) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38816" source="BID" patch="1">38816</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/chsellector/0.1.2/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/chsellector/0.1.2/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christian_hennecke" name="chsellector">
        <vers num="0.1.0" edition="-" />
        <vers prev="1" num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1009" published="2010-03-19" name="CVE-2010-1009" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Educator extension 0.1.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38789" source="BID">38789</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joachim-ruhs" name="educator">
        <vers num="0.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1010" published="2010-03-19" name="CVE-2010-1010" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the MK Wastebasket (mk_wastebasket) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38792" source="BID">38792</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matthias_kall" name="mk_wastebasket">
        <vers prev="1" num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1011" published="2010-03-19" name="CVE-2010-1011" modified="2010-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the myDashboard (mydashboard) extension 0.1.13 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38795" source="BID">38795</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tim_lochmueller" name="mydashboard">
        <vers num="0.0.10" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.7" />
        <vers num="0.0.8" />
        <vers num="0.0.9" />
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers prev="1" num="0.1.13" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1012" published="2010-03-19" name="CVE-2010-1012" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the CleanDB (nf_cleandb) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38810" source="BID">38810</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mathias_schreiber" name="nf_cleandb">
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1013" published="2010-03-19" name="CVE-2010-1013" modified="2010-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38812" source="BID" patch="1">38812</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/pd_diocesedatabase/0.7.13/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/pd_diocesedatabase/0.7.13/</ref>
      <ref url="http://osvdb.org/63034" source="OSVDB" patch="1">63034</ref>
      <ref url="http://secunia.com/advisories/38996" source="SECUNIA" adv="1">38996</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fr.simon_rundell" name="pd_diocesedatabase">
        <vers prev="1" num="0.7.12" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1014" published="2010-03-19" name="CVE-2010-1014" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Reports Logfile View (reports_logview) extension 1.2.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38823" source="BID">38823</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steffen_kamper" name="reports_logview">
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1015" published="2010-03-19" name="CVE-2010-1015" modified="2010-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SAV Filter Alphabetic (sav_filter_abc) extension before 1.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38801" source="BID" patch="1">38801</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/sav_filter_abc/1.0.9/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/sav_filter_abc/1.0.9/</ref>
      <ref url="http://osvdb.org/63033" source="OSVDB" patch="1">63033</ref>
      <ref url="http://secunia.com/advisories/38995" source="SECUNIA" adv="1">38995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laurent_foulloy" name="sav_filter_abc">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1016" published="2010-03-19" name="CVE-2010-1016" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SAV Filter Selectors (sav_filter_selectors) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38804" source="BID" patch="1">38804</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/sav_filter_selectors/1.0.5/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/sav_filter_selectors/1.0.5/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laurent_foulloy" name="sav_filter_selectors">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1017" published="2010-03-19" name="CVE-2010-1017" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SAV Filter Months (sav_filter_months) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38806" source="BID" patch="1">38806</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/sav_filter_months/1.0.5/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/sav_filter_months/1.0.5/</ref>
      <ref url="http://osvdb.org/63035" source="OSVDB" patch="1">63035</ref>
      <ref url="http://secunia.com/advisories/38994" source="SECUNIA" adv="1">38994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="laurent_foulloy" name="sav_filter_months">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1018" published="2010-03-19" name="CVE-2010-1018" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38803" source="BID">38803</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jochen_rau" name="sk_bookreview">
        <vers prev="1" num="0.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1019" published="2010-03-19" name="CVE-2010-1019" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38796" source="BID">38796</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sk-typo3" name="sk_simplegallery">
        <vers num="0.0.1" edition="-" />
        <vers prev="1" num="0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1020" published="2010-03-19" name="CVE-2010-1020" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38796" source="BID">38796</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sk-typo3" name="sk_simplegallery">
        <vers num="0.0.1" edition="-" />
        <vers prev="1" num="0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1021" published="2010-03-19" name="CVE-2010-1021" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Typo3 Quixplorer (t3quixplorer) extension before 1.7.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/t3quixplorer/1.7.1/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/t3quixplorer/1.7.1/</ref>
      <ref url="http://www.securityfocus.com/bid/38818" source="BID">38818</ref>
      <ref url="http://secunia.com/advisories/38993" source="SECUNIA" adv="1">38993</ref>
      <ref url="http://osvdb.org/63036" source="OSVDB">63036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mads_brunn" name="t3quixplorer">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.4.0" />
        <vers num="1.5.0" />
        <vers num="1.6.0" />
        <vers prev="1" num="1.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1022" published="2010-03-19" name="CVE-2010-1022" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/t3sec_saltedpw/0.2.13/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/t3sec_saltedpw/0.2.13/</ref>
      <ref url="http://www.securityfocus.com/bid/38799" source="BID">38799</ref>
      <ref url="http://secunia.com/advisories/38992" source="SECUNIA" adv="1">38992</ref>
    </refs>
    <vuln_soft>
      <prod vendor="marcus_krause" name="t3sec_saltedpw">
        <vers num="0.2.10" />
        <vers num="0.2.11" />
        <vers prev="1" num="0.2.12" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1023" published="2010-03-19" name="CVE-2010-1023" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the UserTask Center, Recent (taskcenter_recent) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/taskcenter_recent/0.2.0/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/taskcenter_recent/0.2.0/</ref>
      <ref url="http://osvdb.org/63037" source="OSVDB" patch="1">63037</ref>
      <ref url="http://www.securityfocus.com/bid/38797" source="BID">38797</ref>
      <ref url="http://secunia.com/advisories/38985" source="SECUNIA" adv="1">38985</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georg_ringer,_patrick_gaumond" name="taskcent_recent">
        <vers num="0.0.7" />
        <vers prev="1" num="0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1024" published="2010-03-19" name="CVE-2010-1024" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38805" source="BID" patch="1">38805</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/tgm_newsletter/0.0.3/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/tgm_newsletter/0.0.3/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56978" source="XF">tgmnewsletter-unspecified-sql-injection(56978)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chris_wederka" name="tgm_newsletter">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1025" published="2010-03-19" name="CVE-2010-1025" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
      <ref url="http://typo3.org/extensions/repository/view/tgm_newsletter/0.0.3/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/tgm_newsletter/0.0.3/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56977" source="XF">tgmnewsletter-unspecified-xss(56977)</ref>
      <ref url="http://www.securityfocus.com/bid/38805" source="BID">38805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chris_wederka" name="tgm_newsletter">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1026" published="2010-03-19" name="CVE-2010-1026" modified="2010-03-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56979" source="XF">cleandbdbal-unspecified-sql-injection(56979)</ref>
      <ref url="http://www.securityfocus.com/bid/38800" source="BID">38800</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mathon_nicolas" name="tmsw_cleandb">
        <vers num="2.0.1" />
        <vers prev="1" num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1027" published="2010-03-19" name="CVE-2010-1027" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Meet Travelmates (travelmate) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56980" source="XF">travelmates-unspecified-sql-injection(56980)</ref>
      <ref url="http://www.securityfocus.com/bid/38802" source="BID">38802</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dietmar_schffer" name="travelmate">
        <vers prev="1" num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1028" published="2010-03-19" name="CVE-2010-1028" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/964549" source="CERT-VN">VU#964549</ref>
      <ref url="https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/" source="MISC">https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552216" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=552216</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-08.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-08.html</ref>
      <ref url="http://www.h-online.com/security/news/item/Zero-day-exploit-for-Firefox-3-6-936124.html" source="MISC">http://www.h-online.com/security/news/item/Zero-day-exploit-for-Firefox-3-6-936124.html</ref>
      <ref url="http://secunia.com/community/forum/thread/show/3592" source="MISC" adv="1">http://secunia.com/community/forum/thread/show/3592</ref>
      <ref url="http://secunia.com/advisories/38608" source="SECUNIA" adv="1">38608</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7969" source="OVAL">oval:org.mitre.oval:def:7969</ref>
      <ref url="http://blog.psi2.de/en/2010/02/20/going-commercial-with-firefox-vulnerabilities/" source="MISC">http://blog.psi2.de/en/2010/02/20/going-commercial-with-firefox-vulnerabilities/</ref>
      <ref url="http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608/" source="CONFIRM">http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608/</ref>
      <ref url="http://blog.mozilla.com/security/2010/02/22/secunia-advisory-sa38608/" source="MISC">http://blog.mozilla.com/security/2010/02/22/secunia-advisory-sa38608/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" edition="a1_pre" />
        <vers num="3.6.1" />
        <vers num="3.7" edition="a1_pre" />
        <vers num="3.7" edition="alpha1" />
        <vers num="3.7" edition="alpha2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1029" published="2010-03-19" name="CVE-2010-1029" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56527" source="XF">webkit-cssselector-dos(56527)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56524" source="XF">safari-chrome-css-bo(56524)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/38398" source="BID">38398</ref>
      <ref url="http://www.exploit-db.com/exploits/11574" source="EXPLOIT-DB">11574</ref>
      <ref url="http://www.exploit-db.com/exploits/11567" source="EXPLOIT-DB">11567</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14301" source="OVAL">oval:org.mitre.oval:def:14301</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.4" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="4.0.249.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1030" published="2010-03-31" name="CVE-2010-1030" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996727024732&amp;w=2" source="HP" patch="1" adv="1">SSRT100010</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996727024732&amp;w=2" source="HP" patch="1" adv="1">SSRT100010</ref>
      <ref url="http://www.securitytracker.com/id?1023772" source="SECTRACK">1023772</ref>
      <ref url="http://www.securityfocus.com/bid/39046" source="BID">39046</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11779" source="OVAL">oval:org.mitre.oval:def:11779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1031" published="2010-04-01" name="CVE-2010-1031" modified="2010-04-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux or ICE-LX) 2.11 and earlier allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996888626964&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02513</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126996888626964&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02513</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0750" source="VUPEN" adv="1">ADV-2010-0750</ref>
      <ref url="http://www.securityfocus.com/bid/39052" source="BID">39052</ref>
      <ref url="http://securitytracker.com/id?1023771" source="SECTRACK">1023771</ref>
      <ref url="http://secunia.com/advisories/39227" source="SECUNIA" adv="1">39227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_control_suite_for_linux">
        <vers num="2.00" />
        <vers num="2.00.01" />
        <vers num="2.10" />
        <vers num="2.10.01" />
        <vers prev="1" num="2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1032" published="2010-04-21" name="CVE-2010-1032" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP HP-UX B.11.11 allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0948" source="VUPEN" adv="1">ADV-2010-0948</ref>
      <ref url="http://secunia.com/advisories/39537" source="SECUNIA">39537</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12146" source="OVAL">oval:org.mitre.oval:def:12146</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02091749" source="HP" adv="1">SSRT100051</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02091749" source="HP" adv="1">SSRT100051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1033" published="2010-04-21" name="CVE-2010-1033" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57938" source="XF">operations-manager-sourceview-bo(57938)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0946" source="VUPEN" adv="1">ADV-2010-0946</ref>
      <ref url="http://www.securityfocus.com/bid/39578" source="BID">39578</ref>
      <ref url="http://www.corelan.be:8800/wp-content/forum-file-uploads/mr_me/hpoperationsmngr.html.txt" source="MISC">http://www.corelan.be:8800/wp-content/forum-file-uploads/mr_me/hpoperationsmngr.html.txt</ref>
      <ref url="http://www.corelan.be:8800/advisories.php?id=CORELAN-10-027" source="MISC">http://www.corelan.be:8800/advisories.php?id=CORELAN-10-027</ref>
      <ref url="http://securitytracker.com/id?1023894" source="SECTRACK">1023894</ref>
      <ref url="http://secunia.com/advisories/39538" source="SECUNIA" adv="1">39538</ref>
      <ref url="http://net-ninja.net/blog/media/blogs/b/exploits/hpoperationsmngr.html.txt" source="MISC">http://net-ninja.net/blog/media/blogs/b/exploits/hpoperationsmngr.html.txt</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02078800" source="HP" adv="1">SSRT100060</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02078800" source="HP">SSRT100060</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="operations_manager">
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="8.10" edition="" />
        <vers num="8.10" edition=":windows" />
        <vers num="8.16" edition="" />
        <vers num="8.16" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1034" published="2010-04-23" name="CVE-2010-1034" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6.0 before 6.0.0.96 on Windows, allows remote authenticated users to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP" patch="1" adv="1">HPSBMA02492</ref>
      <ref url="http://www.osvdb.org/64089" source="OSVDB">64089</ref>
      <ref url="http://securitytracker.com/id?1023909" source="SECTRACK">1023909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1035" published="2010-04-23" name="CVE-2010-1035" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in HP Virtual Machine Manager (VMM) before 6.0 allow remote authenticated users to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1023913" source="SECTRACK">1023913</ref>
      <ref url="http://www.securityfocus.com/bid/39637" source="BID">39637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510881/100/0/threaded" source="HP">HPSBMA02494</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510881/100/0/threaded" source="HP">HPSBMA02494</ref>
      <ref url="http://secunia.com/advisories/39583" source="SECUNIA">39583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_virtual_machine_management">
        <vers num="3.6.1" />
        <vers prev="1" num="3.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1036" published="2010-04-28" name="CVE-2010-1036" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39735" source="BID">39735</ref>
      <ref url="http://securitytracker.com/id?1023927" source="SECTRACK">1023927</ref>
      <ref url="http://secunia.com/advisories/39645" source="SECUNIA" adv="1">39645</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP">SSRT100083</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP">SSRT100083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers num="" edition="sp1" />
        <vers num="2.5" />
        <vers num="2.5.2.0" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.1" edition="sp1" />
        <vers num="4.2" edition="sp1" />
        <vers num="4.2" edition="sp2" />
        <vers num="5.0" edition="sp1" />
        <vers num="5.0" edition="sp2" />
        <vers num="5.0" edition="sp3" />
        <vers num="5.0" edition="sp4" />
        <vers num="5.0" edition="sp5" />
        <vers num="5.1" />
        <vers prev="1" num="5.2" edition="update_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1037" published="2010-04-28" name="CVE-2010-1037" modified="2010-06-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in HP System Insight Manager before 6.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39736" source="BID">39736</ref>
      <ref url="http://securitytracker.com/id?1023927" source="SECTRACK">1023927</ref>
      <ref url="http://secunia.com/advisories/39645" source="SECUNIA" adv="1">39645</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP">HPSBMA02525</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP">HPSBMA02525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers num="" edition="sp1" />
        <vers num="2.5" />
        <vers num="2.5.2.0" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.1" edition="sp1" />
        <vers num="4.2" edition="sp1" />
        <vers num="4.2" edition="sp2" />
        <vers num="5.0" edition="sp1" />
        <vers num="5.0" edition="sp2" />
        <vers num="5.0" edition="sp3" />
        <vers num="5.0" edition="sp4" />
        <vers num="5.0" edition="sp5" />
        <vers num="5.1" />
        <vers prev="1" num="5.2" edition="update_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1038" published="2010-04-28" name="CVE-2010-1038" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP System Insight Manager before 6.0 allows remote authenticated users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39734" source="BID">39734</ref>
      <ref url="http://securitytracker.com/id?1023927" source="SECTRACK">1023927</ref>
      <ref url="http://secunia.com/advisories/39645" source="SECUNIA" adv="1">39645</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP" adv="1">SSRT100083</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127239985506823&amp;w=2" source="HP" adv="1">SSRT100083</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers num="" edition="sp1" />
        <vers num="2.5" />
        <vers num="2.5.2.0" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.1" edition="sp1" />
        <vers num="4.2" edition="sp1" />
        <vers num="4.2" edition="sp2" />
        <vers num="5.0" edition="sp1" />
        <vers num="5.0" edition="sp2" />
        <vers num="5.0" edition="sp3" />
        <vers num="5.0" edition="sp4" />
        <vers num="5.0" edition="sp5" />
        <vers num="5.1" />
        <vers prev="1" num="5.2" edition="update_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1039" published="2010-05-20" name="CVE-2010-1039" modified="2011-07-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40248" source="BID" patch="1">40248</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58718" source="XF">hpux-nfsoncplus-privilege-escalation(58718)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=5088" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=5088</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1213" source="VUPEN" adv="1">ADV-2010-1213</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1212" source="VUPEN" adv="1">ADV-2010-1212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1211" source="VUPEN" adv="1">ADV-2010-1211</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1199" source="VUPEN" adv="1">ADV-2010-1199</ref>
      <ref url="http://www.securitytracker.com/id?1023994" source="SECTRACK">1023994</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511405/100/0/threaded" source="BUGTRAQ">20100520 HP-UX, IBM AIX, SGI IRIX Remote Vulnerability - CVE-2010-1039</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ75465" source="AIXAPAR">IZ75465</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ75440" source="AIXAPAR">IZ75440</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ75369" source="AIXAPAR">IZ75369</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ73874" source="AIXAPAR">IZ73874</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ73757" source="AIXAPAR">IZ73757</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ73681" source="AIXAPAR">IZ73681</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ73599" source="AIXAPAR">IZ73599</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ73590" source="AIXAPAR">IZ73590</ref>
      <ref url="http://www.checkpoint.com/defense/advisories/public/2010/cpai-13-May.html" source="MISC">http://www.checkpoint.com/defense/advisories/public/2010/cpai-13-May.html</ref>
      <ref url="http://securitytracker.com/id?1024016" source="SECTRACK">1024016</ref>
      <ref url="http://secunia.com/advisories/39911" source="SECUNIA">39911</ref>
      <ref url="http://secunia.com/advisories/39835" source="SECUNIA" adv="1">39835</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12103" source="OVAL">oval:org.mitre.oval:def:12103</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11986" source="OVAL">oval:org.mitre.oval:def:11986</ref>
      <ref url="http://osvdb.org/64729" source="OSVDB">64729</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127428077629933&amp;w=2" source="HP" adv="1">HPSBUX02523</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127428077629933&amp;w=2" source="HP" adv="1">HPSBUX02523</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/pcnfsd_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/pcnfsd_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="nfs/oncplus">
        <vers prev="1" num="b.11.31_09" />
      </prod>
      <prod vendor="ibm" name="vios">
        <vers num="1.4" />
        <vers prev="1" num="1.5" />
        <vers num="2.1" />
      </prod>
      <prod vendor="ibm" name="aix">
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="2.2.1" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="4" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.1.12" />
        <vers num="4.3" />
        <vers num="4.3.0" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="430" />
        <vers num="5.1" />
        <vers num="5.1.0.10" />
        <vers num="5.1l" />
        <vers num="5.2" />
        <vers num="5.2.0" />
        <vers num="5.2.0.50" />
        <vers num="5.2.0.54" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers prev="1" num="5.3" />
        <vers num="6.1" />
      </prod>
      <prod vendor="sgi" name="irix">
        <vers num="6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1040" published="2010-03-23" name="CVE-2010-1040" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openpne.jp/archives/4612/" source="CONFIRM" adv="1">http://www.openpne.jp/archives/4612/</ref>
      <ref url="http://www.ipa.go.jp/security/vuln/alert/201003_openpne.html" source="MISC">http://www.ipa.go.jp/security/vuln/alert/201003_openpne.html</ref>
      <ref url="http://secunia.com/advisories/38857" source="SECUNIA" adv="1">38857</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000006.html" source="JVNDB">JVNDB-2010-000006</ref>
      <ref url="http://jvn.jp/en/jp/JVN06874657/index.html" source="JVN">JVN#06874657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tejimaya" name="openpne">
        <vers num="1.6" />
        <vers num="1.8" />
        <vers num="2.10.0" />
        <vers num="2.10.1" />
        <vers num="2.10.10" />
        <vers num="2.10.11" />
        <vers num="2.10.12" />
        <vers num="2.10.13" />
        <vers num="2.10.13.1" />
        <vers num="2.10.2" />
        <vers num="2.10.3" />
        <vers num="2.10.4" />
        <vers num="2.10.4.1" />
        <vers num="2.10.4.2" />
        <vers num="2.10.5" />
        <vers num="2.10.5.1" />
        <vers num="2.10.6" />
        <vers num="2.10.7" />
        <vers num="2.10.8" />
        <vers num="2.10.9" />
        <vers num="2.11.1" />
        <vers num="2.11.2" />
        <vers num="2.11.3" />
        <vers num="2.11.3.1" />
        <vers num="2.11.4" />
        <vers num="2.11.5" />
        <vers num="2.11.5.1" />
        <vers num="2.11.6" />
        <vers num="2.11.7" />
        <vers num="2.12.0" />
        <vers num="2.12.1" />
        <vers num="2.12.10" />
        <vers num="2.12.11" />
        <vers num="2.12.12" />
        <vers num="2.12.13" />
        <vers num="2.12.14" />
        <vers num="2.12.14.1" />
        <vers num="2.12.15" />
        <vers num="2.12.16" />
        <vers num="2.12.17" />
        <vers num="2.12.17.1" />
        <vers num="2.12.18" />
        <vers num="2.12.2" />
        <vers num="2.12.3" />
        <vers num="2.12.4" />
        <vers num="2.12.5" />
        <vers num="2.12.6" />
        <vers num="2.12.7" />
        <vers num="2.12.8" />
        <vers num="2.12.9" />
        <vers num="2.13.0" />
        <vers num="2.13.1" />
        <vers num="2.13.2" />
        <vers num="2.13.3" />
        <vers num="2.13.4" />
        <vers num="2.13.5" />
        <vers num="2.13.6" />
        <vers num="2.13.7" />
        <vers num="2.13.8" />
        <vers num="2.14.0" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.8.1" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.8" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.6.1" />
        <vers num="2.6.6.2" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.9" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.3" />
        <vers num="2.7.4" />
        <vers num="2.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1041" published="2010-03-22" name="CVE-2010-1041" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the single sign-on functionality in the Web Services implementation in IBM DB2 Content Manager (CM) Toolkit 8.3 before FP13 on z/OS and DB2 Information Integrator for Content 8.3 before FP13 has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1PM03804" source="AIXAPAR" patch="1">PM03804</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0656" source="VUPEN" adv="1">ADV-2010-0656</ref>
      <ref url="http://www.securityfocus.com/bid/38833" source="BID">38833</ref>
      <ref url="http://www.osvdb.org/63079" source="OSVDB">63079</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27018205&amp;aid=1" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27018205&amp;aid=1</ref>
      <ref url="http://securitytracker.com/id?1023726" source="SECTRACK">1023726</ref>
      <ref url="http://secunia.com/advisories/39025" source="SECUNIA" adv="1">39025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_content_manager">
        <vers prev="1" num="8.3" edition="fp1" />
        <vers prev="1" num="8.3" edition="fp10" />
        <vers prev="1" num="8.3" edition="fp11" />
        <vers prev="1" num="8.3" edition="fp12" />
        <vers prev="1" num="8.3" edition="fp2" />
        <vers prev="1" num="8.3" edition="fp3" />
        <vers prev="1" num="8.3" edition="fp3a" />
        <vers prev="1" num="8.3" edition="fp4" />
        <vers prev="1" num="8.3" edition="fp5" />
        <vers prev="1" num="8.3" edition="fp6" />
        <vers prev="1" num="8.3" edition="fp7" />
        <vers prev="1" num="8.3" edition="fp8" />
        <vers prev="1" num="8.3" edition="fp9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1042" published="2010-03-22" name="CVE-2010-1042" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57205" source="XF">win-mediaplayer-avi-code-execution(57205)</ref>
      <ref url="http://www.securityfocus.com/bid/38790" source="BID">38790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="11" />
        <vers num="11.0.5721.5145" />
        <vers num="11.0.6000.6324" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1043" published="2010-03-22" name="CVE-2010-1043" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11359" source="EXPLOIT-DB">11359</ref>
      <ref url="http://secunia.com/advisories/38524" source="SECUNIA" adv="1">38524</ref>
      <ref url="http://osvdb.org/62161" source="OSVDB">62161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaxcms" name="jaxcms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1044" published="2010-03-22" name="CVE-2010-1044" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56102" source="XF">oputils-login-sql-injection(56102)</ref>
      <ref url="http://www.securityfocus.com/bid/38082" source="BID">38082</ref>
      <ref url="http://www.exploit-db.com/exploits/11330" source="EXPLOIT-DB">11330</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/oputils_5-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/oputils_5-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="oputils">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1045" published="2010-03-22" name="CVE-2010-1045" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0322" source="VUPEN" adv="1">ADV-2010-0322</ref>
      <ref url="http://www.exploit-db.com/exploits/11352" source="EXPLOIT-DB">11352</ref>
      <ref url="http://secunia.com/advisories/38466" source="SECUNIA" adv="1">38466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="design-cars" name="com_productbook">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1046" published="2010-03-22" name="CVE-2010-1046" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) userid (username) and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0318" source="VUPEN" adv="1">ADV-2010-0318</ref>
      <ref url="http://www.exploit-db.com/exploits/11356" source="EXPLOIT-DB">11356</ref>
      <ref url="http://secunia.com/advisories/38440" source="SECUNIA" adv="1">38440</ref>
      <ref url="http://osvdb.org/62162" source="OSVDB">62162</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryan_marshall" name="rostermain">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1047" published="2010-03-22" name="CVE-2010-1047" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56110" source="XF">musiccity-index-sql-injection(56110)</ref>
      <ref url="http://www.exploit-db.com/exploits/11329" source="EXPLOIT-DB">11329</ref>
      <ref url="http://secunia.com/advisories/38469" source="SECUNIA" adv="1">38469</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/masa2elmc-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/masa2elmc-sql.txt</ref>
      <ref url="http://osvdb.org/62133" source="OSVDB">62133</ref>
    </refs>
    <vuln_soft>
      <prod vendor="masa2el" name="music_city">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1048" published="2010-03-22" name="CVE-2010-1048" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0317" source="VUPEN" adv="1">ADV-2010-0317</ref>
      <ref url="http://www.exploit-db.com/exploits/11357" source="EXPLOIT-DB">11357</ref>
      <ref url="http://secunia.com/advisories/38430" source="SECUNIA" adv="1">38430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="business_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1049" published="2010-03-22" name="CVE-2010-1049" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0317" source="VUPEN" adv="1">ADV-2010-0317</ref>
      <ref url="http://www.exploit-db.com/exploits/11357" source="EXPLOIT-DB">11357</ref>
      <ref url="http://secunia.com/advisories/38430" source="SECUNIA" adv="1">38430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="business_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1050" published="2010-03-22" name="CVE-2010-1050" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11334" source="EXPLOIT-DB">11334</ref>
      <ref url="http://secunia.com/advisories/38494" source="SECUNIA" adv="1">38494</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/audistats-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/audistats-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexandre_dubus" name="audistat">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1051" published="2010-03-22" name="CVE-2010-1051" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38494" source="SECUNIA" adv="1">38494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexandre_dubus" name="audistat">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1052" published="2010-03-22" name="CVE-2010-1052" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38494" source="SECUNIA" adv="1">38494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alexandre_dubus" name="audistat">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1053" published="2010-03-22" name="CVE-2010-1053" modified="2010-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to (a) userlogin.php and (b) managerlogin.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56146" source="XF">zentracking-userlogin-sql-injection(56146)</ref>
      <ref url="http://www.exploit-db.com/exploits/11345" source="EXPLOIT-DB">11345</ref>
      <ref url="http://secunia.com/advisories/38471" source="SECUNIA" adv="1">38471</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zentracking" name="zen_time_tracking">
        <vers prev="1" num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1054" published="2010-03-23" name="CVE-2010-1054" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38734" source="BID">38734</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510066/100/0/threaded" source="BUGTRAQ">20100315 Pars CMS SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/39007" source="SECUNIA" adv="1">39007</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/parscms-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/parscms-sql.txt</ref>
      <ref url="http://osvdb.org/63000" source="OSVDB">63000</ref>
      <ref url="http://osvdb.org/62999" source="OSVDB">62999</ref>
    </refs>
    <vuln_soft>
      <prod vendor="parscms" name="parscms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1055" published="2010-03-23" name="CVE-2010-1055" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[forum_installed] parameter to (1) forum/adminLogin.php and (2) forum/userLogin.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56909" source="XF">osdate-adminlogin-file-include(56909)</ref>
      <ref url="http://www.securityfocus.com/bid/38738" source="BID">38738</ref>
      <ref url="http://www.exploit-db.com/exploits/11755" source="EXPLOIT-DB">11755</ref>
      <ref url="http://secunia.com/advisories/38943" source="SECUNIA" adv="1">38943</ref>
      <ref url="http://osvdb.org/63006" source="OSVDB">63006</ref>
      <ref url="http://osvdb.org/63005" source="OSVDB">63005</ref>
      <ref url="http://evilc0de.blogspot.com/2010/03/osdate-rfi-vuln.html" source="MISC">http://evilc0de.blogspot.com/2010/03/osdate-rfi-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tufat" name="osdate">
        <vers num="2.1.9" />
        <vers num="2.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1056" published="2010-03-23" name="CVE-2010-1056" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38741" source="BID" patch="1">38741</ref>
      <ref url="http://www.rockettheme.com/extensions-updates/638-rokdownloads-10-released" source="CONFIRM" patch="1" adv="1">http://www.rockettheme.com/extensions-updates/638-rokdownloads-10-released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56898" source="XF">rokdownloads-index-file-include(56898)</ref>
      <ref url="http://www.exploit-db.com/exploits/11760" source="EXPLOIT-DB">11760</ref>
      <ref url="http://secunia.com/advisories/38982" source="SECUNIA" adv="1">38982</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomlarokdownloads-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomlarokdownloads-lfi.txt</ref>
      <ref url="http://osvdb.org/62972" source="OSVDB">62972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockettheme" name="com_rokdownloads">
        <vers num="0.91" edition="a" />
        <vers num="0.92" edition="a" />
        <vers num="0.93" edition="a" />
        <vers num="0.94" edition="a" />
        <vers num="0.95" edition="a" />
        <vers num="0.96" edition="a" />
        <vers num="0.97" edition="a" />
        <vers num="0.98" edition="a" />
        <vers prev="1" num="1.0" edition="b1" />
        <vers prev="1" num="1.0" edition="b2" />
        <vers prev="1" num="1.0" edition="b3" />
        <vers prev="1" num="1.0" edition="b4" />
        <vers prev="1" num="1.0" edition="b5" />
        <vers prev="1" num="1.0" edition="b6" />
        <vers prev="1" num="1.0" edition="b7" />
        <vers prev="1" num="1.0" edition="b8" />
        <vers prev="1" num="1.0" edition="b9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1057" published="2010-03-23" name="CVE-2010-1057" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG_CODE parameter to common.inc.php in (1) codelib/cfg/, (2) codelib/sys/, (3) staff/, and (4) staff/app/; and (5) staff/file.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56865" source="XF">adboardscript-common-file-include(56865)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56858" source="XF">adfreely-commoninc-file-include(56858)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0611" source="VUPEN" adv="1">ADV-2010-0611</ref>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://www.exploit-db.com/exploits/11722" source="EXPLOIT-DB">11722</ref>
      <ref url="http://secunia.com/advisories/38947" source="SECUNIA" adv="1">38947</ref>
      <ref url="http://osvdb.org/62926" source="OSVDB">62926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="adfreely">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1058" published="2010-03-23" name="CVE-2010-1058" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56910" source="XF">addressbook-langcode-file-include(56910)</ref>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://www.exploit-db.com/exploits/11754" source="EXPLOIT-DB">11754</ref>
      <ref url="http://secunia.com/advisories/38938" source="SECUNIA" adv="1">38938</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/addressbookscript-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/addressbookscript-lfi.txt</ref>
      <ref url="http://osvdb.org/63003" source="OSVDB">63003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="address_book_script">
        <vers num="1.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1059" published="2010-03-23" name="CVE-2010-1059" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://secunia.com/advisories/38938" source="SECUNIA" adv="1">38938</ref>
      <ref url="http://osvdb.org/63004" source="OSVDB">63004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="address_book_script">
        <vers num="1.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1060" published="2010-03-23" name="CVE-2010-1060" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://www.exploit-db.com/exploits/11775" source="EXPLOIT-DB">11775</ref>
      <ref url="http://secunia.com/advisories/38968" source="SECUNIA" adv="1">38968</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/shorturl-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/shorturl-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="short_url">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1061" published="2010-03-23" name="CVE-2010-1061" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) url/app/common.inc.php and (2) codelib/cfg/common.inc.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://secunia.com/advisories/38968" source="SECUNIA" adv="1">38968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="short_url">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1062" published="2010-03-23" name="CVE-2010-1062" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://www.exploit-db.com/exploits/11773" source="EXPLOIT-DB">11773</ref>
      <ref url="http://secunia.com/advisories/38967" source="SECUNIA" adv="1">38967</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/frecf-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/frecf-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="free_real_estate_contact_form_script">
        <vers num="1.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1063" published="2010-03-23" name="CVE-2010-1063" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php, and (3) staff/app/common.inc.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38731" source="BID">38731</ref>
      <ref url="http://secunia.com/advisories/38967" source="SECUNIA" adv="1">38967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpkobo" name="free_real_estate_contact_form_script">
        <vers num="1.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1064" published="2010-03-23" name="CVE-2010-1064" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55446" source="XF">ajxgalerie-ajxgalerie-info-disclosure(55446)</ref>
      <ref url="http://www.exploit-db.com/exploits/11023" source="EXPLOIT-DB">11023</ref>
      <ref url="http://secunia.com/advisories/38033" source="SECUNIA" adv="1">38033</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/erolife-disclose.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/erolife-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspindir" name="erolife_ajxgaleri_vt">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1065" published="2010-03-23" name="CVE-2010-1065" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55452" source="XF">lebisoftzdefter-lebisoft-info-disclosure(55452)</ref>
      <ref url="http://www.exploit-db.com/exploits/11015" source="EXPLOIT-DB">11015</ref>
      <ref url="http://secunia.com/advisories/38039" source="SECUNIA" adv="1">38039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lebisoft" name="ziyaretci_defteri">
        <vers num="7.4" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1066" published="2010-03-23" name="CVE-2010-1066" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55445" source="XF">awcm-dbbackup-info-disclosure(55445)</ref>
      <ref url="http://www.exploit-db.com/exploits/11025" source="EXPLOIT-DB">11025</ref>
      <ref url="http://secunia.com/advisories/38065" source="SECUNIA" adv="1">38065</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/awcm-backup.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/awcm-backup.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="the-ghost" name="ar_web_content_manager">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1067" published="2010-03-23" name="CVE-2010-1067" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55503" source="XF">emembres-bdemembres-info-disclosure(55503)</ref>
      <ref url="http://www.exploit-db.com/exploits/11098" source="EXPLOIT-DB">11098</ref>
      <ref url="http://secunia.com/advisories/38062" source="SECUNIA" adv="1">38062</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hasmir_alic" name="e-membres">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1068" published="2010-03-23" name="CVE-2010-1068" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55509" source="XF">surgeftp-surgeftpmgr-xss(55509)</ref>
      <ref url="http://www.exploit-db.com/exploits/11092" source="EXPLOIT-DB">11092</ref>
      <ref url="http://secunia.com/advisories/38097" source="SECUNIA" adv="1">38097</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/surgeftp-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/surgeftp-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netwin" name="surgeftp">
        <vers num="2.3a6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1069" published="2010-03-23" name="CVE-2010-1069" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37703" source="BID">37703</ref>
      <ref url="http://www.exploit-db.com/exploits/11080" source="EXPLOIT-DB">11080</ref>
      <ref url="http://secunia.com/advisories/38040" source="SECUNIA" adv="1">38040</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/proarcadescripttogame-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/proarcadescripttogame-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proarcadescript" name="proarcadescript">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1070" published="2010-03-23" name="CVE-2010-1070" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary SQL commands via the seid parameter in a forums viewcat action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55379" source="XF">deviantart-index-sql-injection(55379)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0031" source="VUPEN" adv="1">ADV-2010-0031</ref>
      <ref url="http://www.exploit-db.com/exploits/11002" source="EXPLOIT-DB">11002</ref>
      <ref url="http://secunia.com/advisories/38096" source="SECUNIA" adv="1">38096</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/imagoscriptsdac-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/imagoscriptsdac-sql.txt</ref>
      <ref url="http://osvdb.org/61482" source="OSVDB">61482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagoscripts" name="deviant_art_clone">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1071" published="2010-03-23" name="CVE-2010-1071" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profil.php in phpMDJ 1.0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55516" source="XF">phpmdj-profile-sql-injection(55516)</ref>
      <ref url="http://www.securityfocus.com/bid/37698" source="BID">37698</ref>
      <ref url="http://www.exploit-db.com/exploits/11083" source="EXPLOIT-DB">11083</ref>
      <ref url="http://secunia.com/advisories/33480" source="SECUNIA" adv="1">33480</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpmdj103-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpmdj103-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmdj" name="phpmdj">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1072" published="2010-03-23" name="CVE-2010-1072" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in Sniggabo CMS 2.21 allows remote attackers to inject arbitrary web script or HTML via the q parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55472" source="XF">sniggabocms-search-xss(55472)</ref>
      <ref url="http://www.exploit-db.com/exploits/11049" source="EXPLOIT-DB">11049</ref>
      <ref url="http://secunia.com/advisories/38029" source="SECUNIA" adv="1">38029</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/sniggabocms-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/sniggabocms-xss.txt</ref>
      <ref url="http://greyhathackers.wordpress.com/2010/01/07/sniggabo-cms-v2-21-xss-vulnerability/" source="MISC">http://greyhathackers.wordpress.com/2010/01/07/sniggabo-cms-v2-21-xss-vulnerability/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sniggabo" name="sniggabo_cms">
        <vers num="2.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1073" published="2010-03-23" name="CVE-2010-1073" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the jEmbed-Embed Anything (com_jembed) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a summary action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55443" source="XF">jembed-index-sql-injection(55443)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0047" source="VUPEN" adv="1">ADV-2010-0047</ref>
      <ref url="http://www.exploit-db.com/exploits/11026" source="EXPLOIT-DB">11026</ref>
      <ref url="http://secunia.com/advisories/38112" source="SECUNIA" adv="1">38112</ref>
      <ref url="http://osvdb.org/61510" source="OSVDB">61510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joshprakash" name="com_jembed">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1074" published="2010-03-23" name="CVE-2010-1074" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/676216" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/676216</ref>
      <ref url="http://drupal.org/node/676214" source="CONFIRM" patch="1">http://drupal.org/node/676214</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55453" source="XF">currency-exchange-watchdog-xss(55453)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0063" source="VUPEN" adv="1">ADV-2010-0063</ref>
      <ref url="http://www.securityfocus.com/bid/37649" source="BID">37649</ref>
      <ref url="http://secunia.com/advisories/38121" source="SECUNIA" adv="1">38121</ref>
      <ref url="http://osvdb.org/61587" source="OSVDB">61587</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2bits" name="currency">
        <vers num="4.7.x-1.x-dev" />
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" edition="beta1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="5.x-1.x-dev" />
        <vers num="6.x-1.0" />
        <vers prev="1" num="6.x-1.1" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1075" published="2010-03-23" name="CVE-2010-1075" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to execute arbitrary SQL commands via the subj parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38688" source="SECUNIA" adv="1">38688</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/elcms-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/elcms-sql.txt</ref>
      <ref url="http://osvdb.org/62513" source="OSVDB">62513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="entrylevelcms" name="el_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1076" published="2010-03-23" name="CVE-2010-1076" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Entry Level CMS (EL CMS) allows remote attackers to inject arbitrary web script or HTML via the subj parameter, which is not properly handled in a forced SQL error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38688" source="SECUNIA" adv="1">38688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="entrylevelcms" name="el_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1077" published="2010-03-23" name="CVE-2010-1077" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56439" source="XF">vbseo-vbseourl-file-include(56439)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0442" source="VUPEN" adv="1">ADV-2010-0442</ref>
      <ref url="http://www.exploit-db.com/exploits/11526" source="EXPLOIT-DB">11526</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/vbseo-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/vbseo-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vbseo" name="vbseo">
        <vers num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1078" published="2010-03-23" name="CVE-2010-1078" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in archive.php in XlentProjects SphereCMS 1.1 alpha allows remote attackers to execute arbitrary SQL commands via encoded null bytes ("%00") in the view parameter, which bypasses a protection mechanism.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56423" source="XF">spherecms-archive-sql-injection(56423)</ref>
      <ref url="http://www.securityfocus.com/bid/38309" source="BID">38309</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509603/100/0/threaded" source="BUGTRAQ">20100217 SphereCMS Blind SQL Injection Vulnerability</ref>
      <ref url="http://www.packetstormsecurity.org/1002-exploits/spherecms-sql.txt" source="MISC">http://www.packetstormsecurity.org/1002-exploits/spherecms-sql.txt</ref>
      <ref url="http://www.bugreport.ir/index_68.htm" source="MISC">http://www.bugreport.ir/index_68.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sphere.xlentprojects" name="spherecms">
        <vers num="1.1" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1079" published="2010-03-23" name="CVE-2010-1079" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38387" source="BID">38387</ref>
      <ref url="http://www.sawmill.net/version_history7.html" source="CONFIRM">http://www.sawmill.net/version_history7.html</ref>
      <ref url="http://secunia.com/advisories/38730" source="SECUNIA" adv="1">38730</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sawmill" name="sawmill">
        <vers num="5.0.21" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.10" />
        <vers num="6.2.11" />
        <vers num="6.2.12" />
        <vers num="6.2.13" />
        <vers num="6.2.14" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.2.4" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.8" />
        <vers num="6.2.8a" />
        <vers num="6.2.9" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.10" />
        <vers num="7.0.10a" />
        <vers num="7.0.10b" />
        <vers num="7.0.10c" />
        <vers num="7.0.10d" />
        <vers num="7.0.10e" />
        <vers num="7.0.10f" />
        <vers num="7.0.10g" />
        <vers num="7.0.10h" />
        <vers num="7.0.10i" />
        <vers num="7.0.10j" />
        <vers num="7.0.10k" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.10" />
        <vers num="7.1.11" />
        <vers num="7.1.12" />
        <vers num="7.1.13" />
        <vers num="7.1.14" />
        <vers num="7.1.1b" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.1.7" />
        <vers num="7.1.8" />
        <vers num="7.1.9" />
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.2.10" />
        <vers num="7.2.11" />
        <vers num="7.2.12" />
        <vers num="7.2.13" />
        <vers num="7.2.14" />
        <vers num="7.2.15" />
        <vers num="7.2.16" />
        <vers prev="1" num="7.2.17" />
        <vers num="7.2.2" />
        <vers num="7.2.3" />
        <vers num="7.2.4" />
        <vers num="7.2.5" />
        <vers num="7.2.6" />
        <vers num="7.2.7" />
        <vers num="7.2.8" />
        <vers num="7.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1080" published="2010-03-23" name="CVE-2010-1080" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56430" source="XF">pulsecms-view-xss(56430)</ref>
      <ref url="http://www.securityfocus.com/bid/38356" source="BID">38356</ref>
      <ref url="http://secunia.com/advisories/38650" source="SECUNIA" adv="1">38650</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/pulsecms-xss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/pulsecms-xss.txt</ref>
      <ref url="http://osvdb.org/62475" source="OSVDB">62475</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1081" published="2010-03-23" name="CVE-2010-1081" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38330" source="BID">38330</ref>
      <ref url="http://www.corejoomla.com/component/content/article/1-corejoomla-updates/40-community-polls-v153-security-release.html" source="MISC" adv="1">http://www.corejoomla.com/component/content/article/1-corejoomla-updates/40-community-polls-v153-security-release.html</ref>
      <ref url="http://secunia.com/advisories/38692" source="SECUNIA" adv="1">38692</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/joomlacp-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/joomlacp-lfi.txt</ref>
      <ref url="http://osvdb.org/62506" source="OSVDB">62506</ref>
    </refs>
    <vuln_soft>
      <prod vendor="corejoomla" name="com_communitypolls">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers prev="1" num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1082" published="2010-03-23" name="CVE-2010-1082" modified="2010-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in OI.Blogs 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via directory traversal sequences in the (1) theme parameter to loadStyles.php and the (2) scripts parameter to javascript/loadScripts.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38726" source="SECUNIA" adv="1">38726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openinferno" name="oi.blogs">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1083" published="2010-04-06" name="CVE-2010-1083" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/17/2" source="MLIST" patch="1">[oss-security] 20100217 additional memory leak in USB userspace handling</ref>
      <ref url="http://lwn.net/Articles/375350/" source="MLIST" patch="1">[linux-kernel] 20100221 [80/93] USB: usbfs: properly clean up the as structure on error paths</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0012.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0012.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded" source="BUGTRAQ">20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0723.html" source="REDHAT">RHSA-2010:0723</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0394.html" source="REDHAT">RHSA-2010:0394</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/19/1" source="MLIST">[oss-security] 20100219 Re: CVE request: kernel information leak via userspace USB interface</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/18/7" source="MLIST">[oss-security] 20100218 Re: CVE request: kernel information leak via userspace USB interface</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/18/4" source="MLIST">[oss-security] 20100219 Re: additional memory leak in USB userspace handling</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/17/1" source="MLIST">[oss-security] 20100217 CVE request: kernel information leak via userspace USB interface</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2010_23_kernel.html" source="SUSE">SUSE-SA:2010:023</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100113326" source="CONFIRM">http://support.avaya.com/css/P8/documents/100113326</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100090459" source="CONFIRM">http://support.avaya.com/css/P8/documents/100090459</ref>
      <ref url="http://secunia.com/advisories/46397" source="SECUNIA">46397</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://secunia.com/advisories/39742" source="SECUNIA">39742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10831" source="OVAL">oval:org.mitre.oval:def:10831</ref>
      <ref url="http://lkml.org/lkml/2010/3/30/759" source="MLIST">[linux-kernel] 20100330 [48/89] USB: usbfs: properly clean up the as structure on error paths</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE">SUSE-SA:2010:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers prev="1" num="2.6.32" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1084" published="2010-04-06" name="CVE-2010-1084" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Linux kernel 2.6.18 through 2.6.33, and possibly other versions, allows remote attackers to cause a denial of service (memory corruption) via a large number of Bluetooth sockets, related to the size of sysfs files in (1) net/bluetooth/l2cap.c, (2) net/bluetooth/rfcomm/core.c, (3) net/bluetooth/rfcomm/sock.c, and (4) net/bluetooth/sco.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=576018" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=576018</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/23/1" source="MLIST" patch="1">[oss-security] 20100323 CVE request: kernel: bluetooth: potential bad memory access with sysfs files</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=101545f6fef4a0a3ea8daf0b5b880df2c6a92a69" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=101545f6fef4a0a3ea8daf0b5b880df2c6a92a69</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/38898" source="BID">38898</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0610.html" source="REDHAT">RHSA-2010:0610</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1084" source="MISC">http://security-tracker.debian.org/tracker/CVE-2010-1084</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.32" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.38" />
        <vers num="2.6.27.39" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.40" />
        <vers num="2.6.27.41" />
        <vers num="2.6.27.42" />
        <vers num="2.6.27.43" />
        <vers num="2.6.27.44" />
        <vers num="2.6.27.45" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1085" published="2010-04-06" name="CVE-2010-1085" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=567168" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=567168</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/22/2" source="MLIST" patch="1">[oss-security] 20100222 CVE request: kernel: ALSA: hda-intel: Avoid divide by zero crash</ref>
      <ref url="http://nctritech.net/bugreport.txt" source="MISC" patch="1">http://nctritech.net/bugreport.txt</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/38348" source="BID">38348</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0398.html" source="REDHAT">RHSA-2010:0398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0394.html" source="REDHAT">RHSA-2010:0394</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100090459" source="CONFIRM">http://support.avaya.com/css/P8/documents/100090459</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100088287" source="CONFIRM">http://support.avaya.com/css/P8/documents/100088287</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39649" source="SECUNIA">39649</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10027" source="OVAL">oval:org.mitre.oval:def:10027</ref>
      <ref url="http://lkml.org/lkml/2010/2/5/322" source="MLIST">[linux-kernel] 20100205 PROBLEM: hda-intel divide by zero kernel crash in azx_position_ok()</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers prev="1" num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers prev="1" num="2.6.33" edition="rc4" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1086" published="2010-04-06" name="CVE-2010-1086" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=569237" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=569237</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/01/1" source="MLIST" patch="1">[oss-security] 20100301 CVE request: kernel: dvb-core: ULE decapsulation DoS</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=29e1fa3565a7951cc415c634eb2b78dbdbee151d" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=29e1fa3565a7951cc415c634eb2b78dbdbee151d</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/38479" source="BID">38479</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0398.html" source="REDHAT">RHSA-2010:0398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0394.html" source="REDHAT">RHSA-2010:0394</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2010_23_kernel.html" source="SUSE">SUSE-SA:2010:023</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100090459" source="CONFIRM">http://support.avaya.com/css/P8/documents/100090459</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100088287" source="CONFIRM">http://support.avaya.com/css/P8/documents/100088287</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://secunia.com/advisories/39742" source="SECUNIA">39742</ref>
      <ref url="http://secunia.com/advisories/39649" source="SECUNIA">39649</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10569" source="OVAL">oval:org.mitre.oval:def:10569</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE">SUSE-SA:2010:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers prev="1" num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers prev="1" num="2.6.33" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1087" published="2010-04-06" name="CVE-2010-1087" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allows attackers to cause a denial of service (Oops) via unknown vectors related to truncating a file and an operation that is not interruptible.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=567184" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=567184</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/03/1" source="MLIST" patch="1">[oss-security] 20100303 CVE request: kernel: NFS: Fix an Oops when truncating a file</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9f557cd8073104b39528794d44e129331ded649f" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9f557cd8073104b39528794d44e129331ded649f</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39569" source="BID">39569</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10442" source="OVAL">oval:org.mitre.oval:def:10442</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers prev="1" num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers prev="1" num="2.6.33" edition="rc1" />
        <vers prev="1" num="2.6.33" edition="rc2" />
        <vers prev="1" num="2.6.33" edition="rc3" />
        <vers prev="1" num="2.6.33" edition="rc4" />
        <vers prev="1" num="2.6.33" edition="rc5" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1088" published="2010-04-06" name="CVE-2010-1088" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">fs/namei.c in Linux kernel 2.6.18 through 2.6.34 does not always follow NFS automount "symlinks," which allows attackers to have an unknown impact, related to LOOKUP_FOLLOW.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=567813" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=567813</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/24/3" source="MLIST" patch="1">[oss-security] 20100224 CVE request: kernel: NFS DoS related to "automount" symlinks</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=ac278a9c505092dd82077a2446af8f9fc0d9c095" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=ac278a9c505092dd82077a2446af8f9fc0d9c095</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39044" source="BID">39044</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2010_23_kernel.html" source="SUSE">SUSE-SA:2010:023</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:088" source="MANDRIVA">MDVSA-2010:088</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://secunia.com/advisories/39742" source="SECUNIA">39742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10093" source="OVAL">oval:org.mitre.oval:def:10093</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html" source="SUSE">SUSE-SA:2010:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.32" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.38" />
        <vers num="2.6.27.39" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.40" />
        <vers num="2.6.27.41" />
        <vers num="2.6.27.42" />
        <vers num="2.6.27.43" />
        <vers num="2.6.27.44" />
        <vers num="2.6.27.45" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" />
        <vers num="2.6.34" edition="rc1" />
        <vers num="2.6.34" edition="rc2" />
        <vers num="2.6.34" edition="rc3" />
        <vers num="2.6.34" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1089" published="2010-03-24" name="CVE-2010-1089" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38763" source="SECUNIA" adv="1">38763</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/phptroubleticket-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/phptroubleticket-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phptroubleticket" name="php_trouble_ticket">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1090" published="2010-03-24" name="CVE-2010-1090" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the action parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56573" source="XF">phpmysite-index-sql-injection(56573)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0492" source="VUPEN" adv="1">ADV-2010-0492</ref>
      <ref url="http://www.exploit-db.com/exploits/11588" source="EXPLOIT-DB">11588</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmysite" name="phpmysite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1091" published="2010-03-24" name="CVE-2010-1091" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56574" source="XF">phpmysite-contact-xss(56574)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0492" source="VUPEN" adv="1">ADV-2010-0492</ref>
      <ref url="http://www.exploit-db.com/exploits/11588" source="EXPLOIT-DB">11588</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/phpmysite-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmysite" name="phpmysite">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1092" published="2010-03-24" name="CVE-2010-1092" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56570" source="XF">scriptsfeed-login-sql-injection(56570)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0494" source="VUPEN" adv="1">ADV-2010-0494</ref>
      <ref url="http://www.securityfocus.com/bid/38470" source="BID">38470</ref>
      <ref url="http://www.exploit-db.com/exploits/11592" source="EXPLOIT-DB">11592</ref>
      <ref url="http://secunia.com/advisories/38771" source="SECUNIA" adv="1">38771</ref>
      <ref url="http://osvdb.org/62626" source="OSVDB">62626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsfeed" name="business_directory_software">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1093" published="2010-03-24" name="CVE-2010-1093" modified="2010-12-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a vp action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38476" source="BID">38476</ref>
      <ref url="http://www.bugreport.ir/index_69.htm" source="MISC">http://www.bugreport.ir/index_69.htm</ref>
      <ref url="http://secunia.com/advisories/38775" source="SECUNIA" adv="1">38775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="1024cms" name="1024_cms">
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1094" published="2010-03-24" name="CVE-2010-1094" modified="2010-12-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in DZ EROTIK Auktionshaus V4rgo allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56581" source="XF">v4rgo-news-sql-injection(56581)</ref>
      <ref url="http://www.exploit-db.com/exploits/11582" source="EXPLOIT-DB">11582</ref>
      <ref url="http://secunia.com/advisories/38792" source="SECUNIA" adv="1">38792</ref>
      <ref url="http://osvdb.org/62623" source="OSVDB">62623</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/02/26/dz-erotik-auktionshaus-v-4-rgo-news-php-sql-injection/" source="MISC">http://4004securityproject.wordpress.com/2010/02/26/dz-erotik-auktionshaus-v-4-rgo-news-php-sql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miethner-scripting" name="dz_erotik_auktionshaus_v4rgo">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1095" published="2010-03-24" name="CVE-2010-1095" modified="2010-12-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements &amp; Use Cases (TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0491" source="VUPEN" adv="1">ADV-2010-0491</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jan_schutze" name="truc">
        <vers num="0.10.0" />
        <vers prev="1" num="0.11.0" />
        <vers num="0.9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1096" published="2010-03-24" name="CVE-2010-1096" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in searchmatch.php in ScriptsFeed Dating Software allow remote attackers to execute arbitrary SQL commands via the (1) txtgender and (2) txtlookgender parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0493" source="VUPEN" adv="1">ADV-2010-0493</ref>
      <ref url="http://secunia.com/advisories/38767" source="SECUNIA" adv="1">38767</ref>
      <ref url="http://osvdb.org/62627" source="OSVDB">62627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsfeed" name="dating_software">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1097" published="2010-03-24" name="CVE-2010-1097" modified="2010-12-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38469" source="BID">38469</ref>
      <ref url="http://secunia.com/advisories/38790" source="SECUNIA" adv="1">38790</ref>
      <ref url="http://osvdb.org/62622" source="OSVDB">62622</ref>
      <ref url="http://bbs.wolvez.org/topic/125/" source="MISC">http://bbs.wolvez.org/topic/125/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dedecms" name="dedecms">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1098" published="2010-03-24" name="CVE-2010-1098" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56756" source="XF">microsoft-windows-ani-dos(56756)</ref>
      <ref url="http://www.securityfocus.com/bid/38579" source="BID">38579</ref>
      <ref url="http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/" source="MISC">http://skypher.com/index.php/2010/03/08/ani-file-bitmapinfoheader-biclrused-bounds-check-missing/</ref>
      <ref url="http://code.google.com/p/skylined/issues/detail?id=3" source="MISC">http://code.google.com/p/skylined/issues/detail?id=3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_vista">
        <vers prev="1" num="" edition=":x86" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers prev="1" num="" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1099" published="2010-03-24" name="CVE-2010-1099" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57233" source="XF">safari-tcp-security-bypass(57233)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510283/100/0/threaded" source="BUGTRAQ">20100323 Safari browser port blocking bypassed by integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1100" published="2010-03-24" name="CVE-2010-1100" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in Arora allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57234" source="XF">arora-tcp-security-bypass(57234)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510283/100/0/threaded" source="BUGTRAQ">20100323 Safari browser port blocking bypassed by integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arora-browser" name="arora">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1101" published="2010-03-24" name="CVE-2010-1101" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in Alexander Clauss iCab allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57235" source="XF">icab-tcp-security-bypass(57235)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510283/100/0/threaded" source="BUGTRAQ">20100323 Safari browser port blocking bypassed by integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icab" name="icab">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1102" published="2010-03-24" name="CVE-2010-1102" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in OmniWeb allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57236" source="XF">omniweb-tcp-security-bypass(57236)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510283/100/0/threaded" source="BUGTRAQ">20100323 Safari browser port blocking bypassed by integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnigroup" name="omniweb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1103" published="2010-03-24" name="CVE-2010-1103" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in Stainless allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57237" source="XF">stainless-tcp-security-bypass(57237)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510283/100/0/threaded" source="BUGTRAQ">20100323 Safari browser port blocking bypassed by integer overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mesadynamics" name="stainless">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1104" published="2010-03-25" name="CVE-2010-1104" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://mail.zope.org/pipermail/zope-announce/2010-January/002229.html" source="MLIST" patch="1" adv="1">[zope-announce] 20100112 New Zope2 releases available</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0104" source="VUPEN" patch="1" adv="1">ADV-2010-0104</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55599" source="XF">zope-standarderrormessage-xss(55599)</ref>
      <ref url="http://www.securityfocus.com/bid/37765" source="BID">37765</ref>
      <ref url="http://www.osvdb.org/61655" source="OSVDB">61655</ref>
      <ref url="http://secunia.com/advisories/38007" source="SECUNIA" adv="1">38007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zope">
        <vers num="2.10.0-b1" />
        <vers num="2.10.0-b2" />
        <vers num="2.10.0-c1" />
        <vers num="2.10.0-final" />
        <vers num="2.10.10" />
        <vers num="2.10.11" />
        <vers num="2.10.2" />
        <vers num="2.10.2-b1" />
        <vers num="2.10.2-final" />
        <vers num="2.10.3" />
        <vers num="2.10.3-final" />
        <vers num="2.10.4-final" />
        <vers num="2.10.5" />
        <vers num="2.10.6" />
        <vers num="2.10.7" />
        <vers num="2.10.8" />
        <vers num="2.10.9" />
        <vers num="2.11.0" />
        <vers num="2.11.0a1" />
        <vers num="2.11.0b1" />
        <vers num="2.11.0c1" />
        <vers num="2.11.1" />
        <vers num="2.11.2" />
        <vers num="2.11.3" />
        <vers num="2.11.4" />
        <vers num="2.11.5" />
        <vers num="2.12.0" />
        <vers num="2.12.1" />
        <vers num="2.12.2" />
        <vers num="2.8" />
        <vers num="2.8.0" />
        <vers num="2.8.0-a1" />
        <vers num="2.8.0-a2" />
        <vers num="2.8.0-b1" />
        <vers num="2.8.0-b2" />
        <vers num="2.8.0-final" />
        <vers num="2.8.1" />
        <vers num="2.8.1-b1" />
        <vers num="2.8.1-final" />
        <vers num="2.8.10" />
        <vers num="2.8.11" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.8.5" />
        <vers num="2.8.6" />
        <vers num="2.8.7" />
        <vers num="2.8.8" />
        <vers num="2.8.9" />
        <vers num="2.8.9.1" />
        <vers num="2.9.0" />
        <vers num="2.9.0-b1" />
        <vers num="2.9.0-b2" />
        <vers num="2.9.1" />
        <vers num="2.9.10" />
        <vers num="2.9.11" />
        <vers num="2.9.2" />
        <vers num="2.9.3" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
        <vers num="2.9.6" />
        <vers num="2.9.7" />
        <vers num="2.9.8" />
        <vers num="2.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1105" published="2010-03-25" name="CVE-2010-1105" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cgi/index.php in AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55754" source="XF">advertisementmanager-index-xss(55754)</ref>
      <ref url="http://www.securityfocus.com/bid/40151" source="BID">40151</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/advertisemanager-xssrfitraversal.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/advertisemanager-xssrfitraversal.txt</ref>
      <ref url="http://secunia.com/advisories/38243" source="SECUNIA" adv="1">38243</ref>
      <ref url="http://osvdb.org/61846" source="OSVDB">61846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advertisementmanager" name="advertisementmanager">
        <vers num="3.1.0" />
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1106" published="2010-03-25" name="CVE-2010-1106" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter.  NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55756" source="XF">advertisementmanager-index-file-include(55756)</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/advertisemanager-xssrfitraversal.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/advertisemanager-xssrfitraversal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advertisementmanager" name="advertisementmanager">
        <vers num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1107" published="2010-03-25" name="CVE-2010-1107" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37898" source="BID" patch="1">37898</ref>
      <ref url="http://drupal.org/node/690734" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/690734</ref>
      <ref url="http://drupal.org/node/688636" source="CONFIRM" patch="1">http://drupal.org/node/688636</ref>
      <ref url="http://drupal.org/node/688632" source="CONFIRM" patch="1">http://drupal.org/node/688632</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55770" source="XF">recentcomments-title-xss(55770)</ref>
      <ref url="http://secunia.com/advisories/38281" source="SECUNIA" adv="1">38281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fourkitchens" name="recent_comments">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1108" published="2010-03-25" name="CVE-2010-1108" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/690718" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/690718</ref>
      <ref url="http://drupal.org/node/686428" source="CONFIRM" patch="1">http://drupal.org/node/686428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55769" source="XF">controlpanel-unspecified-xss(55769)</ref>
      <ref url="http://www.securityfocus.com/bid/37890" source="BID">37890</ref>
      <ref url="http://secunia.com/advisories/38280" source="SECUNIA" adv="1">38280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hashmarkconsulting" name="controlpanel">
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="5.x-1.4" />
        <vers num="5.x-1.5" />
        <vers num="6.x-1.0-beta1" />
        <vers num="6.x-1.0-beta2" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1109" published="2010-03-25" name="CVE-2010-1109" modified="2010-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55762" source="XF">phpmysport-unspecified-sql-injection(55762)</ref>
      <ref url="http://www.securityfocus.com/bid/37856" source="BID">37856</ref>
      <ref url="http://secunia.com/advisories/34279" source="SECUNIA" adv="1">34279</ref>
      <ref url="http://phpmysport.sourceforge.net/en/forum/bugs/sujet_2851.html" source="MISC">http://phpmysport.sourceforge.net/en/forum/bugs/sujet_2851.html</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpmysport-sqlaccess.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpmysport-sqlaccess.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="djayp" name="phpmysport">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1110" published="2010-03-25" name="CVE-2010-1110" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in phpMySport 1.4 allows remote attackers to list arbitrary directories via a .. (dot dot) in the current_folder parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55763" source="XF">phpmysport-filemanager-dir-traversal(55763)</ref>
      <ref url="http://www.securityfocus.com/bid/37856" source="BID">37856</ref>
      <ref url="http://phpmysport.sourceforge.net/en/forum/bugs/sujet_2851.html" source="MISC">http://phpmysport.sourceforge.net/en/forum/bugs/sujet_2851.html</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpmysport-sqlaccess.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpmysport-sqlaccess.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="djayp" name="phpmysport">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1111" published="2010-03-25" name="CVE-2010-1111" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and the (2) searchingred parameter to results.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55761" source="XF">jokescompletewebsite-multiple-xss(55761)</ref>
      <ref url="http://www.securityfocus.com/bid/37852" source="BID">37852</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/jokescomplete-xss.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/jokescomplete-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easysitenetwork" name="jokes_complete_website">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1112" published="2010-03-25" name="CVE-2010-1112" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38268" source="SECUNIA" adv="1">38268</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/klonews-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/klonews-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tristan_barczyk" name="klonews">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1113" published="2010-03-25" name="CVE-2010-1113" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55726" source="XF">webservercreator-index-xss(55726)</ref>
      <ref url="http://www.securityfocus.com/bid/37841" source="BID">37841</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="web_server_creator_web_portal">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1114" published="2010-03-25" name="CVE-2010-1114" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55727" source="XF">webservercreator-index-file-include(55727)</ref>
      <ref url="http://www.securityfocus.com/bid/37841" source="BID">37841</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="web_server_creator_web_portal">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1115" published="2010-03-25" name="CVE-2010-1115" modified="2010-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55725" source="XF">webservercreator-customize-dir-traversal(55725)</ref>
      <ref url="http://www.securityfocus.com/bid/37841" source="BID">37841</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/webservercreator-traversalxssrfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="comscripts" name="web_server_creator_web_portal">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1116" published="2010-03-25" name="CVE-2010-1116" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LookMer Music Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for dbmdb/LookMerSarkiMDB.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55751" source="XF">lookmermusicportal-mdb-info-disclosure(55751)</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/lookmer-disclose.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/lookmer-disclose.txt</ref>
      <ref url="http://secunia.com/advisories/38247" source="SECUNIA" adv="1">38247</ref>
      <ref url="http://osvdb.org/61845" source="OSVDB">61845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspindir" name="lookmer_muzik_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1117" published="2010-03-25" name="CVE-2010-1117" modified="2010-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57196" source="XF">ie-base-address-bo(57196)</ref>
      <ref url="http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf" source="MISC">http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf</ref>
      <ref url="http://twitter.com/thezdi/statuses/11003801960" source="MISC">http://twitter.com/thezdi/statuses/11003801960</ref>
      <ref url="http://news.cnet.com/8301-27080_3-20001126-245.html" source="MISC">http://news.cnet.com/8301-27080_3-20001126-245.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010" source="MISC">http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8.0.6001" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1118" published="2010-03-25" name="CVE-2010-1118" modified="2010-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57197" source="XF">ie-unspecified-code-exec(57197)</ref>
      <ref url="http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf" source="MISC">http://vreugdenhilresearch.nl/Pwn2Own-2010-Windows7-InternetExplorer8.pdf</ref>
      <ref url="http://twitter.com/thezdi/statuses/11003801960" source="MISC">http://twitter.com/thezdi/statuses/11003801960</ref>
      <ref url="http://news.cnet.com/8301-27080_3-20001126-245.html" source="MISC">http://news.cnet.com/8301-27080_3-20001126-245.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010" source="MISC">http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1119" published="2010-03-25" name="CVE-2010-1119" modified="2011-09-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID">40620</ref>
      <ref url="http://twitter.com/thezdi/statuses/11001080021" source="MISC">http://twitter.com/thezdi/statuses/11001080021</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://securityreason.com/securityalert/8128" source="SREASON">8128</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7037" source="OVAL">oval:org.mitre.oval:def:7037</ref>
      <ref url="http://news.cnet.com/8301-27080_3-20001126-245.html" source="MISC">http://news.cnet.com/8301-27080_3-20001126-245.html</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010" source="MISC">http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.3" edition="417.9.3" />
        <vers num="2.0.4" />
        <vers num="3" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.0b" />
        <vers num="3.0.1" edition="beta" />
        <vers num="3.0.1b" />
        <vers num="3.0.2" />
        <vers num="3.0.2b" />
        <vers num="3.0.3" />
        <vers num="3.0.3b" />
        <vers num="3.0.4" />
        <vers num="3.0.4b" />
        <vers num="3.1" />
        <vers num="3.1.0" />
        <vers num="3.1.0b" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1120" published="2010-03-25" name="CVE-2010-1120" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Charlie Miller during a Pwn2Own competition at CanSecWest 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://twitter.com/thezdi/statuses/11002504493" source="MISC">http://twitter.com/thezdi/statuses/11002504493</ref>
      <ref url="http://news.cnet.com/8301-27080_3-20001126-245.html" source="MISC">http://news.cnet.com/8301-27080_3-20001126-245.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010" source="MISC">http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1121" published="2010-03-25" name="CVE-2010-1121" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=555109" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=555109</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN" adv="1">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN" adv="1">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN" adv="1">ADV-2010-1557</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1023817" source="SECTRACK">1023817</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-25.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-25.html</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://twitter.com/thezdi/statuses/11005277222" source="MISC">http://twitter.com/thezdi/statuses/11005277222</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA" adv="1">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA" adv="1">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA" adv="1">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA" adv="1">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6844" source="OVAL">oval:org.mitre.oval:def:6844</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10924" source="OVAL">oval:org.mitre.oval:def:10924</ref>
      <ref url="http://news.cnet.com/8301-27080_3-20001126-245.html" source="MISC">http://news.cnet.com/8301-27080_3-20001126-245.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010" source="MISC">http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1122" published="2010-03-25" name="CVE-2010-1122" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552216" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=552216</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:070" source="MANDRIVA">MDVSA-2010:070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12448" source="OVAL">oval:org.mitre.oval:def:12448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1123" published="2010-03-26" name="CVE-2010-1123" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57558" source="XF">deliver-lockfile-dos(57558)</ref>
      <ref url="http://www.securityfocus.com/bid/38924" source="BID">38924</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510306/100/0/threaded" source="BUGTRAQ">20100324 Multiple vulnerabilities in Deliver</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chip_salzenberg" name="deliver">
        <vers num="2.1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1124" published="2010-03-26" name="CVE-2010-1124" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38964" source="BID">38964</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1IZ66710" source="AIXAPAR" adv="1">IZ66710</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
        <vers num="5.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1125" published="2010-03-26" name="CVE-2010-1125" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552255" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=552255</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN" adv="1">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN" adv="1">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN" adv="1">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN" adv="1">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510070/100/0/threaded" source="BUGTRAQ">20100313 ...because you can't get enough of clickjacking</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-31.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-31.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA" adv="1">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA" adv="1">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA" adv="1">40326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13962" source="OVAL">oval:org.mitre.oval:def:13962</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10386" source="OVAL">oval:org.mitre.oval:def:10386</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
        <vers num="2.0a1" edition="" />
        <vers num="2.0a1" edition=":pre" />
        <vers num="2.0a1pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1126" published="2010-03-26" name="CVE-2010-1126" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552255" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=552255</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510070/100/0/threaded" source="BUGTRAQ">20100313 ...because you can't get enough of clickjacking</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1127" published="2010-03-26" name="CVE-2010-1127" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.</descript>
      <descript source="nvd">Per:  http://cwe.mitre.org/data/definitions/476.html

CWE-476: NULL Pointer Dereference</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityreason.com/exploitalert/7731" source="MISC">http://securityreason.com/exploitalert/7731</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-01/0278.html" source="BUGTRAQ">20100128 Re: Microsoft IE 6&amp;7 Crash Exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-01/0237.html" source="BUGTRAQ">20100126 Microsoft IE 6&amp;7 Crash Exploit</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0" />
        <vers num="6.0.2600" />
        <vers num="6.0.2800" />
        <vers num="6.0.2800.1106" />
        <vers num="6.0.2900" />
        <vers num="6.0.2900.2180" />
        <vers num="6.00.2462.0000" />
        <vers num="6.00.2479.0006" />
        <vers num="6.00.2600.0000" />
        <vers num="6.00.2800.1106" />
        <vers num="6.00.2900.2180" />
        <vers num="6.00.3663.0000" />
        <vers num="6.00.3718.0000" />
        <vers num="6.00.3790.0000" />
        <vers num="6.00.3790.1830" />
        <vers num="6.00.3790.3959" />
        <vers num="7.0" edition="beta" />
        <vers num="7.0" edition="beta1" />
        <vers num="7.0" edition="beta2" />
        <vers num="7.0" edition="beta3" />
        <vers num="7.0.5730" edition="unknown" />
        <vers num="7.0.5730" edition="unknown:gold" />
        <vers num="7.0.5730.11" />
        <vers num="7.00.5730.1100" />
        <vers num="7.00.6000.16386" />
        <vers num="7.00.6000.16441" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1128" published="2010-03-26" name="CVE-2010-1128" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0479" source="VUPEN" patch="1" adv="1">ADV-2010-0479</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3081" source="VUPEN">ADV-2010-3081</ref>
      <ref url="http://www.securityfocus.com/bid/38430" source="BID">38430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0919.html" source="REDHAT">RHSA-2010:0919</ref>
      <ref url="http://www.php.net/releases/5_2_13.php" source="CONFIRM" adv="1">http://www.php.net/releases/5_2_13.php</ref>
      <ref url="http://www.php.net/ChangeLog-5.php" source="CONFIRM">http://www.php.net/ChangeLog-5.php</ref>
      <ref url="http://secunia.com/advisories/42410" source="SECUNIA">42410</ref>
      <ref url="http://secunia.com/advisories/38708" source="SECUNIA" adv="1">38708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers prev="1" num="5.2.12" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1129" published="2010-03-26" name="CVE-2010-1129" modified="2010-08-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_13.php" source="CONFIRM" patch="1">http://www.php.net/releases/5_2_13.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1796" source="VUPEN">ADV-2010-1796</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0479" source="VUPEN" adv="1">ADV-2010-0479</ref>
      <ref url="http://www.securityfocus.com/bid/38431" source="BID">38431</ref>
      <ref url="http://www.php.net/ChangeLog-5.php" source="CONFIRM">http://www.php.net/ChangeLog-5.php</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://securitytracker.com/id?1023661" source="SECTRACK">1023661</ref>
      <ref url="http://secunia.com/advisories/40551" source="SECUNIA">40551</ref>
      <ref url="http://secunia.com/advisories/38708" source="SECUNIA" adv="1">38708</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">SSRT100018</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">SSRT100018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1130" published="2010-03-26" name="CVE-2010-1130" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_13.php" source="CONFIRM" patch="1">http://www.php.net/releases/5_2_13.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0479" source="VUPEN" adv="1">ADV-2010-0479</ref>
      <ref url="http://www.php.net/ChangeLog-5.php" source="CONFIRM">http://www.php.net/ChangeLog-5.php</ref>
      <ref url="http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?view=log" source="CONFIRM">http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?view=log</ref>
      <ref url="http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?r1=293036&amp;r2=294272" source="CONFIRM">http://svn.php.net/viewvc/php/php-src/branches/PHP_5_3/ext/session/session.c?r1=293036&amp;r2=294272</ref>
      <ref url="http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?view=log" source="CONFIRM">http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?view=log</ref>
      <ref url="http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?r1=293036&amp;r2=294272" source="CONFIRM">http://svn.php.net/viewvc/php/php-src/branches/PHP_5_2/ext/session/session.c?r1=293036&amp;r2=294272</ref>
      <ref url="http://securitytracker.com/id?1023661" source="SECTRACK">1023661</ref>
      <ref url="http://securityreason.com/securityalert/7008" source="SREASON">7008</ref>
      <ref url="http://securityreason.com/achievement_securityalert/82" source="SREASONRES">20100211 PHP 5.2.12/5.3.1 session.save_path safe_mode and open_basedir bypass</ref>
      <ref url="http://secunia.com/advisories/38708" source="SECUNIA" adv="1">38708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.0.0" edition="rc3" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers num="5.1.5" />
        <vers num="5.1.6" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers prev="1" num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1131" published="2010-03-27" name="CVE-2010-1131" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the &lt;object> substring.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/38884.php" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/38884.php</ref>
      <ref url="http://www.securityfocus.com/bid/38884" source="BID">38884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1132" published="2010-03-27" name="CVE-2010-1132" modified="2011-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://savannah.nongnu.org/bugs/?29136" source="CONFIRM">https://savannah.nongnu.org/bugs/?29136</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=572117" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=572117</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56732" source="XF">spamassassin-expand-command-execution(56732)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0837" source="VUPEN" adv="1">ADV-2010-0837</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0683" source="VUPEN" adv="1">ADV-2010-0683</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0559" source="VUPEN" adv="1">ADV-2010-0559</ref>
      <ref url="http://www.securitytracker.com/id?1023691" source="SECTRACK">1023691</ref>
      <ref url="http://www.securityfocus.com/bid/38578" source="BID">38578</ref>
      <ref url="http://www.exploit-db.com/exploits/11662" source="EXPLOIT-DB">11662</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2021" source="DEBIAN">DSA-2021</ref>
      <ref url="http://secunia.com/advisories/39265" source="SECUNIA" adv="1">39265</ref>
      <ref url="http://secunia.com/advisories/38956" source="SECUNIA" adv="1">38956</ref>
      <ref url="http://secunia.com/advisories/38840" source="SECUNIA" adv="1">38840</ref>
      <ref url="http://osvdb.org/62809" source="OSVDB">62809</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038777.html" source="FEDORA">FEDORA-2010-5112</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038572.html" source="FEDORA">FEDORA-2010-5176</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038535.html" source="FEDORA">FEDORA-2010-5096</ref>
      <ref url="http://bugs.debian.org/573228" source="CONFIRM">http://bugs.debian.org/573228</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-03/0139.html" source="FULLDISC">20100307 Spamassassin Milter Plugin Remote Root</ref>
    </refs>
    <vuln_soft>
      <prod vendor="georg_greve" name="spamassassin_milter_plugin">
        <vers num="0.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1133" published="2010-03-27" name="CVE-2010-1133" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases" source="CONFIRM" patch="1" adv="1">http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56769" source="XF">tikiwiki-unknown-input-sql-injection(56769)</ref>
      <ref url="http://www.securityfocus.com/bid/38608" source="BID">38608</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25435" source="CONFIRM" adv="1">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25435</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25424" source="CONFIRM">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25424</ref>
      <ref url="http://secunia.com/advisories/38896" source="SECUNIA" adv="1">38896</ref>
      <ref url="http://osvdb.org/62800" source="OSVDB">62800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki_cms/groupware">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1134" published="2010-03-27" name="CVE-2010-1134" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38608" source="BID" patch="1">38608</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25429" source="CONFIRM" patch="1" adv="1">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25429</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56769" source="XF">tikiwiki-unknown-input-sql-injection(56769)</ref>
      <ref url="http://secunia.com/advisories/38882" source="SECUNIA" adv="1">38882</ref>
      <ref url="http://osvdb.org/62800" source="OSVDB">62800</ref>
      <ref url="http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases" source="CONFIRM">http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki_cms/groupware">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1135" published="2010-03-27" name="CVE-2010-1135" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases" source="CONFIRM" patch="1">http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56770" source="XF">tikiwiki-userlogout-unspecified(56770)</ref>
      <ref url="http://www.securityfocus.com/bid/38608" source="BID">38608</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25046" source="CONFIRM">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25046</ref>
      <ref url="http://secunia.com/advisories/38896" source="SECUNIA" adv="1">38896</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1136" published="2010-03-27" name="CVE-2010-1136" modified="2010-06-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56771" source="XF">tikiwiki-standardmethod-unspecified(56771)</ref>
      <ref url="http://www.securityfocus.com/bid/38608" source="BID">38608</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25196" source="CONFIRM">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki?view=rev&amp;revision=25196</ref>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki/branches/proposals/3.x/lib/userslib.php?r1=25196&amp;r2=25195&amp;pathrev=25196" source="MISC">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki/branches/proposals/3.x/lib/userslib.php?r1=25196&amp;r2=25195&amp;pathrev=25196</ref>
      <ref url="http://secunia.com/advisories/38882" source="SECUNIA" adv="1">38882</ref>
      <ref url="http://osvdb.org/62801" source="OSVDB">62801</ref>
      <ref url="http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases" source="CONFIRM">http://info.tikiwiki.org/article86-Tiki-Announces-3-5-and-4-2-Releases</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki_cms/groupware">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1137" published="2010-04-01" name="CVE-2010-1137" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0005.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0005.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000086.html" source="MLIST" patch="1" adv="1">[security-announce] 20100329 VMSA-2010-0005 VMware products address vulnerabilities in WebAccess</ref>
      <ref url="http://www.securitytracker.com/id?1023769" source="SECTRACK">1023769</ref>
      <ref url="http://www.securityfocus.com/bid/39037" source="BID">39037</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6863" source="OVAL">oval:org.mitre.oval:def:6863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="esx_server">
        <vers num="3.0.3" />
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="1.0" />
      </prod>
      <prod vendor="vmware" name="virtualcenter">
        <vers num="2.0.2" />
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1138" published="2010-04-12" name="CVE-2010-1138" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware Server 2.x, and VMware Fusion 3.0 before 3.0.1 build 232708 and 2.x before 2.0.7 build 246742 allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets, related to interaction between the guest OS and the host vmware-vmx process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1" adv="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securitytracker.com/id?1023836" source="SECTRACK">1023836</ref>
      <ref url="http://www.securityfocus.com/bid/39395" source="BID">39395</ref>
      <ref url="http://secunia.com/advisories/39215" source="SECUNIA" adv="1">39215</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/39203" source="SECUNIA" adv="1">39203</ref>
      <ref url="http://osvdb.org/63607" source="OSVDB">63607</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.6" />
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="3.0" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="3.0" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1139" published="2010-04-12" name="CVE-2010-1139" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1" adv="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securitytracker.com/id?1023835" source="SECTRACK">1023835</ref>
      <ref url="http://www.securityfocus.com/bid/39407" source="BID">39407</ref>
      <ref url="http://secunia.com/advisories/39215" source="SECUNIA" adv="1">39215</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/39201" source="SECUNIA" adv="1">39201</ref>
      <ref url="http://osvdb.org/63606" source="OSVDB">63606</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="fusion">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="vix_api">
        <vers num="1.6.0" />
        <vers num="1.6.1" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1140" published="2010-04-12" name="CVE-2010-1140" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1" adv="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securityfocus.com/bid/39397" source="BID">39397</ref>
      <ref url="http://securitytracker.com/id?1023834" source="SECTRACK">1023834</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="player">
        <vers num="3.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1141" published="2010-04-12" name="CVE-2010-1141" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file that is stored on a network share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1" adv="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securitytracker.com/id?1023833" source="SECTRACK">1023833</ref>
      <ref url="http://www.securitytracker.com/id?1023832" source="SECTRACK">1023832</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/39198" source="SECUNIA" adv="1">39198</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7020" source="OVAL">oval:org.mitre.oval:def:7020</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="esx">
        <vers num="2.5.5" />
        <vers num="3.0.3" />
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="vmware" name="esxi">
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="3.0" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1142" published="2010-04-12" name="CVE-2010-1142" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs, which might allow Windows guest OS users to gain privileges by placing a Trojan horse program at an unspecified location on the guest OS disk.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1" adv="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securitytracker.com/id?1023833" source="SECTRACK">1023833</ref>
      <ref url="http://www.securitytracker.com/id?1023832" source="SECTRACK">1023832</ref>
      <ref url="http://www.securityfocus.com/bid/39394" source="BID">39394</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2010-04-12-2-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2010-04-12-2-PUB.txt</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/39198" source="SECUNIA" adv="1">39198</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="esx">
        <vers num="2.5.5" />
        <vers num="3.0.3" />
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="vmware" name="esxi">
        <vers num="3.5" />
        <vers num="4.0" />
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="3.0" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1143" published="2010-05-07" name="CVE-2010-1143" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0008.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0008.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000092.html" source="MLIST" patch="1" adv="1">[security-announce] 20100505 VMSA-2010-0008 VMware View 3.1.3 addresses an important cross-site scripting vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/39949" source="BID">39949</ref>
      <ref url="http://securitytracker.com/id?1023945" source="SECTRACK">1023945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="view_manager">
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1144" reject="1" published="2010-04-06" name="CVE-2010-1144" modified="2010-04-06">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-0751, CVE-2010-1277.  Reason: this candidate was intended for one issue, but it was accidentally assigned to two different issues, one for libnids and another for Zabbix.  Notes: All CVE users should consult CVE-2010-0751 (libnids) and CVE-2010-1277 (Zabbix) to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2010-1145" reject="1" published="2010-05-20" name="CVE-2010-1145" modified="2010-05-20">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-4498.  Reason: This candidate is a duplicate of CVE-2009-4498.  Notes: All CVE users should reference CVE-2009-4498 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1146" published="2010-04-12" name="CVE-2010-1146" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by deleting a file under .reiserfs_priv/xattrs/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=127076012022155&amp;w=2" source="MLIST" patch="1">[linux-kernel] 20100408 [PATCH #3] reiserfs: Fix permissions on .reiserfs_priv</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=568041" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=568041</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57782" source="XF">kernel-reiserfs-privilege-escalation(57782)</ref>
      <ref url="http://www.securityfocus.com/bid/39344" source="BID">39344</ref>
      <ref url="http://www.exploit-db.com/exploits/12130" source="EXPLOIT-DB">12130</ref>
      <ref url="http://secunia.com/advisories/39316" source="SECUNIA" adv="1">39316</ref>
      <ref url="http://osvdb.org/63601" source="OSVDB">63601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" />
        <vers num="2.6.33.1" />
        <vers prev="1" num="2.6.33.2" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1147" published="2010-04-06" name="CVE-2010-1147" modified="2010-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary code via a long MyINFO message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=579206" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=579206</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1044" source="VUPEN">ADV-2010-1044</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1023" source="VUPEN">ADV-2010-1023</ref>
      <ref url="http://www.securityfocus.com/bid/39129" source="BID">39129</ref>
      <ref url="http://www.securityfocus.com/archive/1/510428" source="BUGTRAQ">20100331 OpenDcHub 0.8.1 Remote Code Execution Exploit</ref>
      <ref url="http://www.indahax.com/exploits/opendchub-0-8-1-remote-code-execution-exploit#more-600" source="MISC">http://www.indahax.com/exploits/opendchub-0-8-1-remote-code-execution-exploit#more-600</ref>
      <ref url="http://secunia.com/advisories/39664" source="SECUNIA">39664</ref>
      <ref url="http://openwall.com/lists/oss-security/2010/04/03/1" source="MLIST">[oss-security] 20100403 CVE Request -- OpenDCHub v0.8.1 -- Stack overflow by handling a specially-crafted MyINFO message</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127051570728944&amp;w=2" source="MLIST">[oss-security] 20100406 Re: CVE Request -- OpenDCHub v0.8.1 -- Stack overflow by handling a specially-crafted MyINFO message</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/040421.html" source="FEDORA">FEDORA-2010-6426</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/040380.html" source="FEDORA">FEDORA-2010-6415</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/040360.html" source="FEDORA">FEDORA-2010-6478</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576308" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576308</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roshan_singh" name="open_direct_connect_hub">
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1148" published="2010-04-12" name="CVE-2010-1148" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL nameidata (aka nd) field in a POSIX file-creation request to a server that supports UNIX extensions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=579445" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=579445</ref>
      <ref url="http://xorl.wordpress.com/2010/04/05/linux-kernel-unix-extensions-cifs-null-pointer-dereference/" source="MISC">http://xorl.wordpress.com/2010/04/05/linux-kernel-unix-extensions-cifs-null-pointer-dereference/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57561" source="XF">linux-kernel-cifscreate-dos(57561)</ref>
      <ref url="http://www.securityfocus.com/bid/39186" source="BID">39186</ref>
      <ref url="http://secunia.com/advisories/39344" source="SECUNIA" adv="1">39344</ref>
      <ref url="http://openwall.com/lists/oss-security/2010/04/06/2" source="MLIST">[oss-security] 20100405 Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127045779122119&amp;w=2" source="MLIST">[oss-security] 20100405 Re: CVE request: kernel: cifs: cifs_create() NULL pointer dereference</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127045754521927&amp;w=2" source="MLIST">[oss-security] 20100405 CVE request: kernel: cifs: cifs_create() NULL pointer dereference</ref>
      <ref url="http://lists.samba.org/archive/linux-cifs-client/2010-April/005757.html" source="MLIST">[linux-cifs-client] 20100404 [patch] skip posix open if nameidata is null</ref>
      <ref url="http://lists.samba.org/archive/linux-cifs-client/2010-April/005746.html" source="MLIST">[linux-cifs-client] 20100402 [patch] skip posix open if nameidata is null</ref>
      <ref url="http://lists.samba.org/archive/linux-cifs-client/2010-April/005742.html" source="MLIST">[linux-cifs-client] 20100402 [patch] skip posix open if nameidata is null</ref>
      <ref url="http://lists.samba.org/archive/linux-cifs-client/2010-April/005741.html" source="MLIST">[linux-cifs-client] 20100402 [patch] skip posix open if nameidata is null</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" />
        <vers num="2.6.33.1" />
        <vers prev="1" num="2.6.33.2" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1149" published="2010-04-12" name="CVE-2010-1149" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/556651" source="CONFIRM">https://launchpad.net/bugs/556651</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=580005" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=580005</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=594261" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=594261</ref>
      <ref url="https://bugs.freedesktop.org/show_bug.cgi?id=27494" source="CONFIRM">https://bugs.freedesktop.org/show_bug.cgi?id=27494</ref>
      <ref url="http://www.securityfocus.com/bid/39265" source="BID">39265</ref>
      <ref url="http://secunia.com/advisories/39332" source="SECUNIA" adv="1">39332</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039060.html" source="FEDORA">FEDORA-2010-6296</ref>
      <ref url="http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4" source="CONFIRM">http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="udisks">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1150" published="2010-04-20" name="CVE-2010-1150" modified="2010-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">MediaWiki before 1.15.3, and 1.6.x before 1.16.0beta2, does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to conduct phishing attacks by arranging for a victim to login to the attacker's account and then execute a crafted user script, related to a "login CSRF" issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-April/000090.html" source="MLIST" patch="1" adv="1">[mediawiki-announce] 20100407 MediaWiki security update: 1.15.3 and 1.16.0beta2</ref>
      <ref url="http://download.wikimedia.org/mediawiki/1.16/mediawiki-1.16.0beta2.patch.gz" source="CONFIRM" patch="1">http://download.wikimedia.org/mediawiki/1.16/mediawiki-1.16.0beta2.patch.gz</ref>
      <ref url="http://download.wikimedia.org/mediawiki/1.15/mediawiki-1.15.3.patch.gz" source="CONFIRM" patch="1">http://download.wikimedia.org/mediawiki/1.15/mediawiki-1.15.3.patch.gz</ref>
      <ref url="https://bugzilla.wikimedia.org/show_bug.cgi?id=23076" source="CONFIRM">https://bugzilla.wikimedia.org/show_bug.cgi?id=23076</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=580418" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=580418</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1055" source="VUPEN">ADV-2010-1055</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/08/4" source="MLIST">[oss-security] 20100407 Re: CVE Request: MediaWiki 1.15.3 -- Login CSRF</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/07/1" source="MLIST">[oss-security] 20100406 CVE Request: MediaWiki 1.15.3 -- Login CSRF</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2041" source="DEBIAN">DSA-2041</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_16_0beta2/phase3/RELEASE-NOTES" source="CONFIRM">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_16_0beta2/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_3/phase3/RELEASE-NOTES" source="CONFIRM">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_3/phase3/RELEASE-NOTES</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.10.0" edition="rc1" />
        <vers num="1.10.0" edition="rc2" />
        <vers num="1.10.1" />
        <vers num="1.10.2" />
        <vers num="1.10.3" />
        <vers num="1.10.4" />
        <vers num="1.11.0" edition="rc1" />
        <vers num="1.11.1" />
        <vers num="1.11.2" />
        <vers num="1.12.0" edition="rc1" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.3" />
        <vers num="1.12.4" />
        <vers num="1.13.0" edition="rc1" />
        <vers num="1.13.0" edition="rc2" />
        <vers num="1.13.1" />
        <vers num="1.13.2" />
        <vers num="1.13.3" />
        <vers num="1.13.4" />
        <vers num="1.14.0" edition="rc1" />
        <vers num="1.14.1" />
        <vers num="1.15.0" edition="rc1" />
        <vers num="1.15.1" />
        <vers prev="1" num="1.15.2" />
        <vers num="1.16.0" edition="beta1" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.10" />
        <vers num="1.6.11" />
        <vers num="1.6.12" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.6.9" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.9.0" edition="rc2" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1151" published="2010-04-20" name="CVE-2010-1151" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=578168" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=578168</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1148" source="VUPEN">ADV-2010-1148</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0908" source="VUPEN">ADV-2010-0908</ref>
      <ref url="http://www.securityfocus.com/bid/39538" source="BID">39538</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:081" source="MANDRIVA">MDVSA-2010:081</ref>
      <ref url="http://secunia.com/advisories/39823" source="SECUNIA">39823</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041340.html" source="FEDORA">FEDORA-2010-6359</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041326.html" source="FEDORA">FEDORA-2010-6323</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apache_http_server">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1152" published="2010-04-12" name="CVE-2010-1152" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=oss-security&amp;m=127075808518733&amp;w=2" source="MLIST" patch="1">[oss-security] 20100408 Re: CVE request -- memcached</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127075341110616&amp;w=2" source="MLIST" patch="1">[oss-security] 20100408 Re: CVE request -- memcached</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127074597129559&amp;w=2" source="MLIST" patch="1">[oss-security] 20100408 CVE request -- memcached</ref>
      <ref url="http://github.com/memcached/memcached/commit/d9cd01ede97f4145af9781d448c62a3318952719" source="CONFIRM" patch="1">http://github.com/memcached/memcached/commit/d9cd01ede97f4145af9781d448c62a3318952719</ref>
      <ref url="http://github.com/memcached/memcached/commit/75cc83685e103bc8ba380a57468c8f04413033f9" source="CONFIRM" patch="1">http://github.com/memcached/memcached/commit/75cc83685e103bc8ba380a57468c8f04413033f9</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0442" source="VUPEN">ADV-2011-0442</ref>
      <ref url="http://securitytracker.com/id?1023839" source="SECTRACK">1023839</ref>
      <ref url="http://secunia.com/advisories/39306" source="SECUNIA" adv="1">39306</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://code.google.com/p/memcached/issues/detail?id=102" source="CONFIRM">http://code.google.com/p/memcached/issues/detail?id=102</ref>
      <ref url="http://blogs.sun.com/security/entry/input_validation_vulnerability_in_memcached" source="CONFIRM">http://blogs.sun.com/security/entry/input_validation_vulnerability_in_memcached</ref>
    </refs>
    <vuln_soft>
      <prod vendor="memcachedb" name="memcached">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="1.0.0" edition="beta" />
        <vers num="1.0.1" edition="beta" />
        <vers num="1.0.2" edition="beta" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" edition="beta" />
        <vers num="1.1.12" />
        <vers num="1.2.0" edition="beta" />
        <vers num="1.2.1" edition="beta" />
        <vers num="1.2.2" />
        <vers num="1.2.8" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers prev="1" num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1153" published="2010-04-20" name="CVE-2010-1153" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/12/1" source="MLIST">[oss-security] 20100412 Re: CVE request: typo3 remote command execution</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-008/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-008/</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127092306209177&amp;w=2" source="MLIST">[oss-security] 20100410 CVE request: typo3 remote command execution</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.3.0" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1155" published="2010-04-16" name="CVE-2010-1155" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0856" source="VUPEN" patch="1" adv="1">ADV-2010-0856</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57790" source="XF">irssi-hostname-mitm(57790)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1110" source="VUPEN">ADV-2010-1110</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0987" source="VUPEN">ADV-2010-0987</ref>
      <ref url="http://www.ubuntu.com/usn/USN-929-1" source="UBUNTU">USN-929-1</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.497301" source="SLACKWARE">SSA:2010-116-01</ref>
      <ref url="http://secunia.com/advisories/39797" source="SECUNIA">39797</ref>
      <ref url="http://secunia.com/advisories/39620" source="SECUNIA">39620</ref>
      <ref url="http://secunia.com/advisories/39365" source="SECUNIA" adv="1">39365</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127119240204394&amp;w=2" source="MLIST">[oss-security] 20100413 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127116251220784&amp;w=2" source="MLIST">[oss-security] 20100413 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127110132019166&amp;w=2" source="MLIST">[oss-security] 20100412 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127098845125270&amp;w=2" source="MLIST">[oss-security] 20100411 CVE request: irssi 0.8.15</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041054.html" source="FEDORA">FEDORA-2010-6629</ref>
      <ref url="http://irssi.org/news/ChangeLog" source="CONFIRM">http://irssi.org/news/ChangeLog</ref>
      <ref url="http://irssi.org/news" source="CONFIRM">http://irssi.org/news</ref>
      <ref url="http://github.com/ensc/irssi-proxy/commit/85bbc05b21678e80423815d2ef1dfe26208491ab" source="CONFIRM">http://github.com/ensc/irssi-proxy/commit/85bbc05b21678e80423815d2ef1dfe26208491ab</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irssi" name="irssi">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.10" edition="rc5" />
        <vers num="0.8.10" edition="rc6" />
        <vers num="0.8.10" edition="rc7" />
        <vers num="0.8.10" edition="rc8" />
        <vers num="0.8.11" edition="rc1" />
        <vers num="0.8.11" edition="rc2" />
        <vers num="0.8.12" edition="rc1" />
        <vers num="0.8.13" edition="rc1" />
        <vers num="0.8.14" />
        <vers prev="1" num="0.8.15" edition="rc1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1156" published="2010-04-16" name="CVE-2010-1156" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">core/nicklist.c in Irssi before 0.8.15 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an attempted fuzzy nick match at the instant that a victim leaves a channel.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'NULL Pointer Dereference'

</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0856" source="VUPEN" patch="1" adv="1">ADV-2010-0856</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57791" source="XF">irssi-unspecified-dos(57791)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1110" source="VUPEN">ADV-2010-1110</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0987" source="VUPEN">ADV-2010-0987</ref>
      <ref url="http://www.ubuntu.com/usn/USN-929-1" source="UBUNTU">USN-929-1</ref>
      <ref url="http://svn.irssi.org/cgi-bin/viewvc.cgi/irssi/trunk/src/core/nicklist.c?root=irssi&amp;r1=4922&amp;r2=5126" source="CONFIRM">http://svn.irssi.org/cgi-bin/viewvc.cgi/irssi/trunk/src/core/nicklist.c?root=irssi&amp;r1=4922&amp;r2=5126</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.497301" source="SLACKWARE">SSA:2010-116-01</ref>
      <ref url="http://securitytracker.com/id?1023845" source="SECTRACK">1023845</ref>
      <ref url="http://secunia.com/advisories/39797" source="SECUNIA">39797</ref>
      <ref url="http://secunia.com/advisories/39620" source="SECUNIA">39620</ref>
      <ref url="http://secunia.com/advisories/39365" source="SECUNIA" adv="1">39365</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127119240204394&amp;w=2" source="MLIST">[oss-security] 20100413 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127115784314970&amp;w=2" source="MLIST">[oss-security] 20100413 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127111071631857&amp;w=2" source="MLIST">[oss-security] 20100412 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127110132019166&amp;w=2" source="MLIST">[oss-security] 20100412 Re: CVE request: irssi 0.8.15</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127098845125270&amp;w=2" source="MLIST">[oss-security] 20100411 CVE request: irssi 0.8.15</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041054.html" source="FEDORA">FEDORA-2010-6629</ref>
      <ref url="http://irssi.org/news/ChangeLog" source="CONFIRM">http://irssi.org/news/ChangeLog</ref>
      <ref url="http://irssi.org/news" source="CONFIRM">http://irssi.org/news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irssi" name="irssi">
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.10" edition="rc5" />
        <vers num="0.8.10" edition="rc6" />
        <vers num="0.8.10" edition="rc7" />
        <vers num="0.8.10" edition="rc8" />
        <vers num="0.8.11" edition="rc1" />
        <vers num="0.8.11" edition="rc2" />
        <vers num="0.8.12" edition="rc1" />
        <vers num="0.8.13" edition="rc1" />
        <vers num="0.8.14" />
        <vers prev="1" num="0.8.15" edition="rc1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1157" published="2010-04-23" name="CVE-2010-1157" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=936541" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=936541</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=936540" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=936540</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN" adv="1">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0980" source="VUPEN" adv="1">ADV-2010-0980</ref>
      <ref url="http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" source="CONFIRM">http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39635" source="BID">39635</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510879/100/0/threaded" source="BUGTRAQ">20100421 [SECURITY] CVE-2010-1157: Apache Tomcat information disclosure vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0897.html" source="REDHAT">RHSA-2011:0897</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0896.html" source="REDHAT">RHSA-2011:0896</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:177" source="MANDRIVA">MDVSA-2010:177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" source="MANDRIVA">MDVSA-2010:176</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://secunia.com/advisories/43310" source="SECUNIA" adv="1">43310</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA" adv="1">42368</ref>
      <ref url="http://secunia.com/advisories/39574" source="SECUNIA" adv="1">39574</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.18" />
        <vers num="5.5.19" />
        <vers num="5.5.2" />
        <vers num="5.5.20" />
        <vers num="5.5.21" />
        <vers num="5.5.22" />
        <vers num="5.5.23" />
        <vers num="5.5.24" />
        <vers num="5.5.25" />
        <vers num="5.5.26" />
        <vers num="5.5.27" />
        <vers num="5.5.28" />
        <vers num="5.5.29" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.12" />
        <vers num="6.0.13" />
        <vers num="6.0.14" />
        <vers num="6.0.15" />
        <vers num="6.0.16" />
        <vers num="6.0.17" />
        <vers num="6.0.18" />
        <vers num="6.0.19" />
        <vers num="6.0.2" />
        <vers num="6.0.20" />
        <vers num="6.0.24" />
        <vers num="6.0.26" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1158" published="2010-04-20" name="CVE-2010-1158" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the regular expression engine in Perl 5.8.x allows context-dependent attackers to cause a denial of service (stack consumption and application crash) by matching a crafted regular expression against a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=580605" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=580605</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/14/3" source="MLIST">[oss-security] 20100414 Re: CVE Request -- perl v5.8.* -- stack overflow by processing certain regex (Gentoo BTS#313565 / RH BZ#580605)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/08/9" source="MLIST">[oss-security] 20100408 CVE Request -- perl v5.8.* -- stack overflow by processing certain regex (Gentoo BTS#313565 / RH BZ#580605)</ref>
      <ref url="http://perldoc.perl.org/perl5100delta.html" source="CONFIRM">http://perldoc.perl.org/perl5100delta.html</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=313565" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=313565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl" name="perl">
        <vers num="5.8.1" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.8.7" />
        <vers num="5.8.8" />
        <vers num="5.8.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1160" published="2010-04-16" name="CVE-2010-1160" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1023891" source="SECTRACK">1023891</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/14/4" source="MLIST">[oss-security] 20100414 CVE request: GNU nano (minor)</ref>
      <ref url="http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&amp;root=nano&amp;view=markup" source="CONFIRM">http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&amp;root=nano&amp;view=markup</ref>
      <ref url="http://secunia.com/advisories/39444" source="SECUNIA" adv="1">39444</ref>
      <ref url="http://lists.gnu.org/archive/html/nano-devel/2010-04/msg00000.html" source="MLIST">[Nano-devel] 20100407 New prerelease for security tweaks</ref>
      <ref url="http://drosenbe.blogspot.com/2010/03/nano-as-root.html" source="MISC">http://drosenbe.blogspot.com/2010/03/nano-as-root.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="nano">
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.9" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.17" />
        <vers num="0.9.18" />
        <vers num="0.9.19" />
        <vers num="0.9.2" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9.99pre1" />
        <vers num="0.9.99pre2" />
        <vers num="0.9.99pre3" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.99pre1" />
        <vers num="1.1.99pre2" />
        <vers num="1.1.99pre3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.9.99pre1" />
        <vers num="1.9.99pre2" />
        <vers num="1.9.99pre3" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.9" />
        <vers num="2.1.99pre1" />
        <vers num="2.1.99pre2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers prev="1" num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1161" published="2010-04-16" name="CVE-2010-1161" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1023891" source="SECTRACK">1023891</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/14/4" source="MLIST">[oss-security] 20100414 CVE request: GNU nano (minor)</ref>
      <ref url="http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&amp;root=nano&amp;view=markup" source="CONFIRM">http://svn.savannah.gnu.org/viewvc/trunk/nano/ChangeLog?revision=4503&amp;root=nano&amp;view=markup</ref>
      <ref url="http://secunia.com/advisories/39444" source="SECUNIA" adv="1">39444</ref>
      <ref url="http://lists.gnu.org/archive/html/nano-devel/2010-04/msg00000.html" source="MLIST">[Nano-devel] 20100407 New prerelease for security tweaks</ref>
      <ref url="http://drosenbe.blogspot.com/2010/03/nano-as-root.html" source="MISC">http://drosenbe.blogspot.com/2010/03/nano-as-root.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="nano">
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.9" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.17" />
        <vers num="0.9.18" />
        <vers num="0.9.19" />
        <vers num="0.9.2" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="0.9.99pre1" />
        <vers num="0.9.99pre2" />
        <vers num="0.9.99pre3" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.99pre1" />
        <vers num="1.1.99pre2" />
        <vers num="1.1.99pre3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.9.99pre1" />
        <vers num="1.9.99pre2" />
        <vers num="1.9.99pre3" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.9" />
        <vers num="2.1.99pre1" />
        <vers num="2.1.99pre2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers prev="1" num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1162" published="2010-04-20" name="CVE-2010-1162" modified="2010-11-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6da8d866d0d39e9509ff826660f6a86a6757c966" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=6da8d866d0d39e9509ff826660f6a86a6757c966</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=582076" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=582076</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/16/1" source="MLIST">[oss-security] 20100415 Re: CVE request: kernel: tty: release_one_tty() forgets to put pids</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/15/2" source="MLIST">[oss-security] 20100415 CVE request: kernel: tty: release_one_tty() forgets to put pids</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/15/1" source="MLIST">[oss-security] 20100414 Re: Couple of kernel issues</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/14/1" source="MLIST">[oss-security] 20100414 Couple of kernel issues</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.34-rc4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.34-rc4</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers prev="1" num="2.6.34" edition="rc1" />
        <vers prev="1" num="2.6.34" edition="rc2" />
        <vers prev="1" num="2.6.34" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1163" published="2010-04-16" name="CVE-2010-1163" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57836" source="XF">sudo-sudoefit-privilege-escalation(57836)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1019" source="VUPEN">ADV-2010-1019</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0956" source="VUPEN">ADV-2010-0956</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0949" source="VUPEN">ADV-2010-0949</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0904" source="VUPEN">ADV-2010-0904</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0895" source="VUPEN" adv="1">ADV-2010-0895</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0881" source="VUPEN" adv="1">ADV-2010-0881</ref>
      <ref url="http://www.ubuntu.com/usn/USN-928-1" source="UBUNTU">USN-928-1</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/sudoedit_escalate2.html" source="CONFIRM">http://www.sudo.ws/sudo/alerts/sudoedit_escalate2.html</ref>
      <ref url="http://www.securityfocus.com/bid/39468" source="BID">39468</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514489/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0075-1 sudo</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510880/100/0/threaded" source="BUGTRAQ">20100422 Re: sudoedit local privilege escalation through PATH manipulation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510846/100/0/threaded" source="BUGTRAQ">20100420 Re: sudoedit local privilege escalation through PATH manipulation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510827/100/0/threaded" source="BUGTRAQ">20100419 sudoedit local privilege escalation through PATH manipulation</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0361.html" source="REDHAT">RHSA-2010:0361</ref>
      <ref url="http://www.osvdb.org/63878" source="OSVDB">63878</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:078" source="MANDRIVA">MDVSA-2010:078</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2010-0075" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2010-0075</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.577019" source="SLACKWARE">SSA:2010-110-01</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/39543" source="SECUNIA">39543</ref>
      <ref url="http://secunia.com/advisories/39474" source="SECUNIA" adv="1">39474</ref>
      <ref url="http://secunia.com/advisories/39399" source="SECUNIA">39399</ref>
      <ref url="http://secunia.com/advisories/39384" source="SECUNIA" adv="1">39384</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9382" source="OVAL">oval:org.mitre.oval:def:9382</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039986.html" source="FEDORA">FEDORA-2010-6756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6.8" />
        <vers num="1.6.8_p1" />
        <vers num="1.6.8_p12" />
        <vers num="1.6.8_p2" />
        <vers num="1.6.8_p5" />
        <vers num="1.6.8_p7" />
        <vers num="1.6.8_p8" />
        <vers num="1.6.8_p9" />
        <vers num="1.6.8p7" />
        <vers num="1.6.9_p17" />
        <vers num="1.6.9_p18" />
        <vers num="1.6.9_p19" />
        <vers num="1.6.9_p20" />
        <vers num="1.6.9_p21" />
        <vers num="1.6.9_p22" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2p1" />
        <vers num="1.7.2p2" />
        <vers num="1.7.2p3" />
        <vers num="1.7.2p4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1164" published="2010-04-20" name="CVE-2010-1164" modified="2010-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter to the Colour Picker page; the (3) formName parameter, (4) element parameter, or (5) full name field to the User Picker page; the (6) formName parameter, (7) element parameter, or (8) group name field to the Group Picker page; the (9) announcement_preview_banner_st parameter to unspecified components, related to the Announcement Banner Preview page; unspecified vectors involving the (10) groupnames.jsp, (11) indexbrowser.jsp, (12) classpath-debug.jsp, (13) viewdocument.jsp, or (14) cleancommentspam.jsp page; the (15) portletKey parameter to runportleterror.jsp; the (16) URI to issuelinksmall.jsp; the (17) afterURL parameter to screenshot-redirecter.jsp; or the (18) HTTP Referrer header to 500page.jsp, as exploited in the wild in April 2010.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://jira.atlassian.com/browse/JRA-21004" source="CONFIRM" patch="1" adv="1">http://jira.atlassian.com/browse/JRA-21004</ref>
      <ref url="http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2010-04-16" source="CONFIRM" patch="1" adv="1">http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2010-04-16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57827" source="XF">jira-element-xss(57827)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57826" source="XF">jira-groupnames-xss(57826)</ref>
      <ref url="http://www.securityfocus.com/bid/39485" source="BID">39485</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/16/4" source="MLIST">[oss-security] 20100416 Re: CVE Request: JIRA Issues</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/16/3" source="MLIST">[oss-security] 20100416 CVE Request: JIRA Issues</ref>
      <ref url="http://secunia.com/advisories/39353" source="SECUNIA" adv="1">39353</ref>
      <ref url="http://jira.atlassian.com/browse/JRA-20994" source="CONFIRM" adv="1">http://jira.atlassian.com/browse/JRA-20994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atlassian" name="jira">
        <vers num="3.12" />
        <vers num="3.12.1" />
        <vers num="3.12.2" />
        <vers num="3.12.3" />
        <vers num="3.13" />
        <vers num="3.13.1" />
        <vers num="3.13.2" />
        <vers num="3.13.3" />
        <vers num="3.13.4" />
        <vers num="3.13.5" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1165" published="2010-04-20" name="CVE-2010-1165" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://jira.atlassian.com/browse/JRA-21004" source="CONFIRM" patch="1" adv="1">http://jira.atlassian.com/browse/JRA-21004</ref>
      <ref url="http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2010-04-16" source="CONFIRM" patch="1" adv="1">http://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2010-04-16</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57828" source="XF">jira-pathsettings-priv-escalation(57828)</ref>
      <ref url="http://www.securityfocus.com/bid/39485" source="BID">39485</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/16/4" source="MLIST">[oss-security] 20100416 Re: CVE Request: JIRA Issues</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/16/3" source="MLIST">[oss-security] 20100416 CVE Request: JIRA Issues</ref>
      <ref url="http://secunia.com/advisories/39353" source="SECUNIA" adv="1">39353</ref>
      <ref url="http://jira.atlassian.com/browse/JRA-20995" source="CONFIRM" adv="1">http://jira.atlassian.com/browse/JRA-20995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="atlassian" name="jira">
        <vers num="3.12" />
        <vers num="3.12.1" />
        <vers num="3.12.2" />
        <vers num="3.12.3" />
        <vers num="3.13" />
        <vers num="3.13.1" />
        <vers num="3.13.2" />
        <vers num="3.13.3" />
        <vers num="3.13.4" />
        <vers num="3.13.5" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1166" published="2010-04-29" name="CVE-2010-1166" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://cgit.freedesktop.org/xorg/xserver/commit/?id=d2f813f7db" source="MISC" patch="1">http://cgit.freedesktop.org/xorg/xserver/commit/?id=d2f813f7db</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0382.html" source="REDHAT">RHSA-2010:0382</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=582601" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=582601</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495733" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495733</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1185" source="VUPEN">ADV-2010-1185</ref>
      <ref url="http://www.ubuntu.com/usn/USN-939-1" source="UBUNTU">USN-939-1</ref>
      <ref url="http://securitytracker.com/id?1023929" source="SECTRACK">1023929</ref>
      <ref url="http://secunia.com/advisories/39834" source="SECUNIA">39834</ref>
      <ref url="http://secunia.com/advisories/39650" source="SECUNIA" adv="1">39650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10112" source="OVAL">oval:org.mitre.oval:def:10112</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x" name="x.org">
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1167" published="2010-05-07" name="CVE-2010-1167" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1) message header or (2) POP3 UIDL list.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511140/100/0/threaded" source="BUGTRAQ" patch="1">20100506 fetchmail security announcement fetchmail-SA-2010-02 (CVE-2010-1167)</ref>
      <ref url="http://www.fetchmail.info/fetchmail-SA-2010-02.txt" source="CONFIRM" patch="1">http://www.fetchmail.info/fetchmail-SA-2010-02.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39556" source="BID">39556</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:107" source="MANDRIVA">MDVSA-2011:107</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?group_id=1824&amp;release_id=17512" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?group_id=1824&amp;release_id=17512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="4.6.3" />
        <vers num="4.6.4" />
        <vers num="4.6.5" />
        <vers num="4.6.6" />
        <vers num="4.6.7" />
        <vers num="4.6.8" />
        <vers num="4.6.9" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.7.3" />
        <vers num="4.7.4" />
        <vers num="4.7.5" />
        <vers num="4.7.6" />
        <vers num="4.7.7" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.8" />
        <vers num="5.1.0" />
        <vers num="5.1.4" />
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.3" />
        <vers num="5.3.8" />
        <vers num="5.4.0" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.4.5" />
        <vers num="5.5.0" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.6.0" />
        <vers num="5.7.0" />
        <vers num="5.7.2" />
        <vers num="5.7.4" />
        <vers num="5.8" />
        <vers num="5.8.1" />
        <vers num="5.8.11" />
        <vers num="5.8.13" />
        <vers num="5.8.14" />
        <vers num="5.8.17" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.0" />
        <vers num="5.9.10" />
        <vers num="5.9.11" />
        <vers num="5.9.13" />
        <vers num="5.9.4" />
        <vers num="5.9.5" />
        <vers num="5.9.8" />
        <vers num="6.0.0" />
        <vers num="6.1.0" />
        <vers num="6.1.3" />
        <vers num="6.2.0" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.3" />
        <vers num="6.2.4" />
        <vers num="6.2.5" />
        <vers num="6.2.5.1" />
        <vers num="6.2.5.2" />
        <vers num="6.2.5.4" />
        <vers num="6.2.6" edition="pre4" />
        <vers num="6.2.6" edition="pre8" />
        <vers num="6.2.6" edition="pre9" />
        <vers num="6.2.9" edition="rc10" />
        <vers num="6.2.9" edition="rc3" />
        <vers num="6.2.9" edition="rc4" />
        <vers num="6.2.9" edition="rc5" />
        <vers num="6.2.9" edition="rc7" />
        <vers num="6.2.9" edition="rc8" />
        <vers num="6.2.9" edition="rc9" />
        <vers num="6.3.0" />
        <vers num="6.3.1" />
        <vers num="6.3.10" />
        <vers num="6.3.11" />
        <vers num="6.3.12" />
        <vers num="6.3.13" />
        <vers num="6.3.14" />
        <vers num="6.3.15" />
        <vers num="6.3.16" />
        <vers num="6.3.2" />
        <vers num="6.3.3" />
        <vers num="6.3.4" />
        <vers num="6.3.5" />
        <vers num="6.3.6" edition="rc1" />
        <vers num="6.3.6" edition="rc2" />
        <vers num="6.3.6" edition="rc3" />
        <vers num="6.3.6" edition="rc4" />
        <vers num="6.3.6" edition="rc5" />
        <vers num="6.3.7" />
        <vers num="6.3.8" />
        <vers prev="1" num="6.3.9" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1168" published="2010-06-21" name="CVE-2010-1168" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving implicitly called methods and implicitly blessed objects, as demonstrated by the (a) DESTROY and (b) AUTOLOAD methods, related to "automagic methods."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=576508" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=576508</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3075" source="VUPEN">ADV-2010-3075</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0458.html" source="REDHAT" adv="1">RHSA-2010:0458</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0457.html" source="REDHAT" adv="1">RHSA-2010:0457</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/20/5" source="MLIST">[oss-security] 20100520 CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:116" source="MANDRIVA">MDVSA-2010:116</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:115" source="MANDRIVA">MDVSA-2010:115</ref>
      <ref url="http://securitytracker.com/id?1024062" source="SECTRACK" adv="1">1024062</ref>
      <ref url="http://secunia.com/advisories/42402" source="SECUNIA">42402</ref>
      <ref url="http://secunia.com/advisories/40052" source="SECUNIA" adv="1">40052</ref>
      <ref url="http://secunia.com/advisories/40049" source="SECUNIA" adv="1">40049</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9807" source="OVAL">oval:org.mitre.oval:def:9807</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7424" source="OVAL">oval:org.mitre.oval:def:7424</ref>
      <ref url="http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes" source="CONFIRM">http://cpansearch.perl.org/src/RGARCIA/Safe-2.27/Changes</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_1168_vulnerability_in</ref>
      <ref url="http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html" source="CONFIRM">http://blogs.perl.org/users/rafael_garcia-suarez/2010/03/new-safepm-fixes-security-hole.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rafael_garcia-suarez" name="safe">
        <vers num="2.08" />
        <vers num="2.09" />
        <vers num="2.11" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.20" />
        <vers num="2.21" />
        <vers num="2.22" />
        <vers num="2.23" />
        <vers num="2.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1169" published="2010-05-19" name="CVE-2010-1169" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.postgresql.org/about/news.1203" source="CONFIRM" patch="1">http://www.postgresql.org/about/news.1203</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=588269" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=588269</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=582615" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=582615</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58693" source="XF">postgresql-safe-code-execution(58693)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1221" source="VUPEN">ADV-2010-1221</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1207" source="VUPEN">ADV-2010-1207</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1198" source="VUPEN">ADV-2010-1198</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1197" source="VUPEN">ADV-2010-1197</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1182" source="VUPEN">ADV-2010-1182</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1167" source="VUPEN" adv="1">ADV-2010-1167</ref>
      <ref url="http://www.securitytracker.com/id?1023988" source="SECTRACK">1023988</ref>
      <ref url="http://www.securityfocus.com/bid/40215" source="BID">40215</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0430.html" source="REDHAT">RHSA-2010:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0429.html" source="REDHAT">RHSA-2010:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0428.html" source="REDHAT">RHSA-2010:0428</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0427.html" source="REDHAT">RHSA-2010:0427</ref>
      <ref url="http://www.postgresql.org/support/security" source="CONFIRM">http://www.postgresql.org/support/security</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-4-4.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-4-4.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-3-11.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-3-11.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-2-17.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-2-17.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-1-21.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-1-21.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-0-25.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-0-25.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-7-4-29.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-7-4-29.html</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/20/5" source="MLIST">[oss-security] 20100520 CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:103" source="MANDRIVA">MDVSA-2010:103</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2051" source="DEBIAN">DSA-2051</ref>
      <ref url="http://secunia.com/advisories/39939" source="SECUNIA">39939</ref>
      <ref url="http://secunia.com/advisories/39898" source="SECUNIA">39898</ref>
      <ref url="http://secunia.com/advisories/39845" source="SECUNIA" adv="1">39845</ref>
      <ref url="http://secunia.com/advisories/39820" source="SECUNIA">39820</ref>
      <ref url="http://secunia.com/advisories/39815" source="SECUNIA">39815</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10645" source="OVAL">oval:org.mitre.oval:def:10645</ref>
      <ref url="http://osvdb.org/64755" source="OSVDB">64755</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041591.html" source="FEDORA">FEDORA-2010-8723</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041579.html" source="FEDORA">FEDORA-2010-8715</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041559.html" source="FEDORA">FEDORA-2010-8696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.12" />
        <vers num="7.4.13" />
        <vers num="7.4.14" />
        <vers num="7.4.15" />
        <vers num="7.4.16" />
        <vers num="7.4.17" />
        <vers num="7.4.18" />
        <vers num="7.4.19" />
        <vers num="7.4.2" />
        <vers num="7.4.20" />
        <vers num="7.4.21" />
        <vers num="7.4.22" />
        <vers num="7.4.23" />
        <vers num="7.4.24" />
        <vers num="7.4.25" />
        <vers num="7.4.26" />
        <vers num="7.4.27" />
        <vers num="7.4.28" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.11" />
        <vers num="8.0.12" />
        <vers num="8.0.13" />
        <vers num="8.0.14" />
        <vers num="8.0.15" />
        <vers num="8.0.16" />
        <vers num="8.0.17" />
        <vers num="8.0.18" />
        <vers num="8.0.19" />
        <vers num="8.0.2" />
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.0.23" />
        <vers num="8.0.24" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.10" />
        <vers num="8.1.11" />
        <vers num="8.1.12" />
        <vers num="8.1.13" />
        <vers num="8.1.14" />
        <vers num="8.1.15" />
        <vers num="8.1.16" />
        <vers num="8.1.17" />
        <vers num="8.1.18" />
        <vers num="8.1.19" />
        <vers num="8.1.2" />
        <vers num="8.1.20" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8" />
        <vers num="8.1.9" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.10" />
        <vers num="8.2.11" />
        <vers num="8.2.12" />
        <vers num="8.2.13" />
        <vers num="8.2.14" />
        <vers num="8.2.15" />
        <vers num="8.2.16" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.2.8" />
        <vers num="8.2.9" />
        <vers num="8.3" />
        <vers num="8.3.1" />
        <vers num="8.3.10" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.3.7" />
        <vers num="8.3.8" />
        <vers num="8.3.9" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.2" />
        <vers num="8.4.3" />
        <vers num="9.0.0" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1170" published="2010-05-19" name="CVE-2010-1170" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code from the pltcl_modules table regardless of the table's ownership and permissions, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Tcl code by creating this table and inserting a crafted Tcl script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1167" source="VUPEN" patch="1" adv="1">ADV-2010-1167</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=583072" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=583072</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1221" source="VUPEN">ADV-2010-1221</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1207" source="VUPEN">ADV-2010-1207</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1198" source="VUPEN">ADV-2010-1198</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1197" source="VUPEN">ADV-2010-1197</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1182" source="VUPEN">ADV-2010-1182</ref>
      <ref url="http://www.securitytracker.com/id?1023987" source="SECTRACK">1023987</ref>
      <ref url="http://www.securityfocus.com/bid/40215" source="BID">40215</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0430.html" source="REDHAT">RHSA-2010:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0429.html" source="REDHAT">RHSA-2010:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0428.html" source="REDHAT">RHSA-2010:0428</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0427.html" source="REDHAT">RHSA-2010:0427</ref>
      <ref url="http://www.postgresql.org/support/security" source="CONFIRM">http://www.postgresql.org/support/security</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-4-4.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-4-4.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-3-11.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-3-11.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-2-17.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-2-17.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-1-21.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-1-21.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-0-25.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-0-25.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-7-4-29.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-7-4-29.html</ref>
      <ref url="http://www.postgresql.org/about/news.1203" source="CONFIRM" adv="1">http://www.postgresql.org/about/news.1203</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/20/5" source="MLIST">[oss-security] 20100520 CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:103" source="MANDRIVA">MDVSA-2010:103</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2051" source="DEBIAN">DSA-2051</ref>
      <ref url="http://secunia.com/advisories/39939" source="SECUNIA">39939</ref>
      <ref url="http://secunia.com/advisories/39898" source="SECUNIA">39898</ref>
      <ref url="http://secunia.com/advisories/39845" source="SECUNIA" adv="1">39845</ref>
      <ref url="http://secunia.com/advisories/39820" source="SECUNIA">39820</ref>
      <ref url="http://secunia.com/advisories/39815" source="SECUNIA">39815</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10510" source="OVAL">oval:org.mitre.oval:def:10510</ref>
      <ref url="http://osvdb.org/64757" source="OSVDB">64757</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041591.html" source="FEDORA">FEDORA-2010-8723</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041579.html" source="FEDORA">FEDORA-2010-8715</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041559.html" source="FEDORA">FEDORA-2010-8696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.12" />
        <vers num="7.4.13" />
        <vers num="7.4.14" />
        <vers num="7.4.15" />
        <vers num="7.4.16" />
        <vers num="7.4.17" />
        <vers num="7.4.18" />
        <vers num="7.4.19" />
        <vers num="7.4.2" />
        <vers num="7.4.20" />
        <vers num="7.4.21" />
        <vers num="7.4.22" />
        <vers num="7.4.23" />
        <vers num="7.4.24" />
        <vers num="7.4.25" />
        <vers num="7.4.26" />
        <vers num="7.4.27" />
        <vers num="7.4.28" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.11" />
        <vers num="8.0.12" />
        <vers num="8.0.13" />
        <vers num="8.0.14" />
        <vers num="8.0.15" />
        <vers num="8.0.16" />
        <vers num="8.0.17" />
        <vers num="8.0.18" />
        <vers num="8.0.19" />
        <vers num="8.0.2" />
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.0.23" />
        <vers num="8.0.24" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.10" />
        <vers num="8.1.11" />
        <vers num="8.1.12" />
        <vers num="8.1.13" />
        <vers num="8.1.14" />
        <vers num="8.1.15" />
        <vers num="8.1.16" />
        <vers num="8.1.17" />
        <vers num="8.1.18" />
        <vers num="8.1.19" />
        <vers num="8.1.2" />
        <vers num="8.1.20" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8" />
        <vers num="8.1.9" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.10" />
        <vers num="8.2.11" />
        <vers num="8.2.12" />
        <vers num="8.2.13" />
        <vers num="8.2.14" />
        <vers num="8.2.15" />
        <vers num="8.2.16" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.2.8" />
        <vers num="8.2.9" />
        <vers num="8.3" />
        <vers num="8.3.1" />
        <vers num="8.3.10" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.3.7" />
        <vers num="8.3.8" />
        <vers num="8.3.9" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.2" />
        <vers num="8.4.3" />
        <vers num="9.0.0" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1171" published="2011-04-18" name="CVE-2010-1171" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0434.html" source="REDHAT" patch="1" adv="1">RHSA-2011:0434</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=584118" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=584118</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66690" source="XF">rhnss-xmlrpcapi-info-disclosure(66690)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0967" source="VUPEN" adv="1">ADV-2011-0967</ref>
      <ref url="http://www.securitytracker.com/id?1025316" source="SECTRACK">1025316</ref>
      <ref url="http://www.securityfocus.com/bid/47316" source="BID">47316</ref>
      <ref url="http://secunia.com/advisories/44150" source="SECUNIA" adv="1">44150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="network_satellite">
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1172" published="2010-08-20" name="CVE-2010-1172" modified="2011-01-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=585394" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=585394</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/61041" source="XF">glib-property-security-bypass(61041)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3097" source="VUPEN">ADV-2010-3097</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2063" source="VUPEN" adv="1">ADV-2010-2063</ref>
      <ref url="http://www.securityfocus.com/bid/42347" source="BID">42347</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0616.html" source="REDHAT">RHSA-2010:0616</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100113103" source="CONFIRM">http://support.avaya.com/css/P8/documents/100113103</ref>
      <ref url="http://secunia.com/advisories/42397" source="SECUNIA">42397</ref>
      <ref url="http://secunia.com/advisories/40925" source="SECUNIA" adv="1">40925</ref>
      <ref url="http://secunia.com/advisories/40908" source="SECUNIA" adv="1">40908</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html" source="SUSE">SUSE-SR:2010:022</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html" source="SUSE">SUSE-SR:2010:020</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
      <ref url="http://cgit.freedesktop.org/dbus/dbus-glib/commit/?h=rhel5&amp;id=9a6bce9b615abca6068348c1606ba8eaf13d9ae0" source="CONFIRM">http://cgit.freedesktop.org/dbus/dbus-glib/commit/?h=rhel5&amp;id=9a6bce9b615abca6068348c1606ba8eaf13d9ae0</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="dbus-glib">
        <vers num="0.73" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1173" published="2010-05-07" name="CVE-2010-1173" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is enabled, allows remote attackers to cause a denial of service (system crash) via an SCTPChunkInit packet containing multiple invalid parameters that require a large amount of error data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git;a=commit;h=5fa782c2f5ef6c2e4f04d3e228412c9b4a4c8809" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git;a=commit;h=5fa782c2f5ef6c2e4f04d3e228412c9b4a4c8809</ref>
      <ref url="http://article.gmane.org/gmane.linux.network/159531" source="MLIST" patch="1">[netdev] 20100428 Re: [PATCH]: sctp: Fix skb_over_panic resulting from multiple invalid parameter errors (CVE-2010-1173) (v4)</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=584645" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=584645</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0474.html" source="REDHAT">RHSA-2010:0474</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/29/6" source="MLIST">[oss-security] 20100429 Re: CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/29/1" source="MLIST">[oss-security] 20100429 CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/40218" source="SECUNIA">40218</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11416" source="OVAL">oval:org.mitre.oval:def:11416</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127251068407878&amp;w=2" source="MLIST">[oss-security] 20100429 Re: CVE-2010-1173 kernel: skb_over_panic resulting from multiple invalid parameter errors</ref>
      <ref url="http://kbase.redhat.com/faq/docs/DOC-31052" source="CONFIRM">http://kbase.redhat.com/faq/docs/DOC-31052</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33" edition="rc7" />
        <vers num="2.6.33" edition="rc8" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers prev="1" num="2.6.33.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1174" published="2010-03-29" name="CVE-2010-1174" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57165" source="XF">cisco-tftp-dos(57165)</ref>
      <ref url="http://www.securityfocus.com/bid/38968" source="BID">38968</ref>
      <ref url="http://www.exploit-db.com/exploits/11878" source="EXPLOIT-DB">11878</ref>
      <ref url="http://secunia.com/advisories/39116" source="SECUNIA" adv="1">39116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="tftp_server">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1175" published="2010-03-29" name="CVE-2010-1175" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510280/100/0/threaded" source="BUGTRAQ">20100320 Internet Explorer 7.0 0day Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1176" published="2010-03-29" name="CVE-2010-1176" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods, possibly a related issue to CVE-2009-0075.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38989" source="BID">38989</ref>
      <ref url="http://www.exploit-db.com/exploits/11891" source="EXPLOIT-DB">11891</ref>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc1.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc1.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1177" published="2010-03-29" name="CVE-2010-1177" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38994" source="BID">38994</ref>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc2.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc2.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1178" published="2010-03-29" name="CVE-2010-1178" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57993" source="XF">safari-iphone-javascript-dos(57993)</ref>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc3.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc3.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1179" published="2010-03-29" name="CVE-2010-1179" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to CVE-2007-0024.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38990" source="BID">38990</ref>
      <ref url="http://www.exploit-db.com/exploits/11890" source="EXPLOIT-DB">11890</ref>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc4.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc4.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1180" published="2010-03-29" name="CVE-2010-1180" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57992" source="XF">safari-iphone-throw-code-execution(57992)</ref>
      <ref url="http://www.securityfocus.com/bid/38992" source="BID">38992</ref>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc5.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc5.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1181" published="2010-03-29" name="CVE-2010-1181" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a MARQUEE element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://nishantdaspatnaik.yolasite.com/ipodpoc6.php" source="MISC">http://nishantdaspatnaik.yolasite.com/ipodpoc6.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1182" published="2010-03-29" name="CVE-2010-1182" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the administrative console in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.9 on z/OS have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0609" source="VUPEN" adv="1">ADV-2010-0609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.6" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1183" published="2010-03-29" name="CVE-2010-1183" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink attack on the /tmp/CLEANUP temporary file, related to use of Update Manager.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57149" source="XF">solaris-update-manager-multiple-symlink(57149)</ref>
      <ref url="http://www.securityfocus.com/bid/38928" source="BID">38928</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510311/100/0/threaded" source="BUGTRAQ">20100324 Symlink attack with Solaris Update manager and Sun Patch Cluster</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510305/100/0/threaded" source="BUGTRAQ">20100324 Symlink attack with Solaris Update manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1184" published="2010-03-29" name="CVE-2010-1184" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57978" source="XF">ms-keyboard-xor-command-execution(57978)</ref>
      <ref url="http://www.theregister.co.uk/2010/03/26/open_source_wireless_sniffer/" source="MISC">http://www.theregister.co.uk/2010/03/26/open_source_wireless_sniffer/</ref>
      <ref url="http://www.remote-exploit.org/?p=437" source="MISC">http://www.remote-exploit.org/?p=437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="27mhz_wireless_keyboard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1185" published="2010-03-29" name="CVE-2010-1185" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a handshake packet to TCP port 7210.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56950" source="XF">maxdb-serv-bo(56950)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-032/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-032/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0643" source="VUPEN" adv="1">ADV-2010-0643</ref>
      <ref url="http://www.securitytracker.com/id?1023719" source="SECTRACK">1023719</ref>
      <ref url="http://www.securityfocus.com/bid/38769" source="BID">38769</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510125/100/0/threaded" source="BUGTRAQ">20100316 ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38955" source="SECUNIA" adv="1">38955</ref>
      <ref url="http://osvdb.org/63047" source="OSVDB">63047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="maxdb">
        <vers num="7.4.3.32" />
        <vers num="7.6.0.37" />
        <vers num="7.6.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1186" published="2010-04-07" name="CVE-2010-1186" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://wordpress.org/extend/plugins/nextgen-gallery/changelog/" source="CONFIRM" patch="1">http://wordpress.org/extend/plugins/nextgen-gallery/changelog/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57562" source="XF">nextgen-mode-xss(57562)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0821" source="VUPEN">ADV-2010-0821</ref>
      <ref url="http://www.securityfocus.com/bid/39250" source="BID">39250</ref>
      <ref url="http://www.exploit-db.com/exploits/12098" source="EXPLOIT-DB">12098</ref>
      <ref url="http://www.coresecurity.com/content/nextgen-gallery-xss-vulnerability" source="MISC">http://www.coresecurity.com/content/nextgen-gallery-xss-vulnerability</ref>
      <ref url="http://secunia.com/advisories/39341" source="SECUNIA">39341</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alex_rabe" name="nextgen_gallery">
        <vers num="0.33" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.36" />
        <vers num="0.37" />
        <vers num="0.39" />
        <vers num="0.40" />
        <vers num="0.41" />
        <vers num="0.42" />
        <vers num="0.43" />
        <vers num="0.50" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.5.0" />
        <vers prev="1" num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1187" published="2010-03-31" name="CVE-2010-1187" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which triggers a NULL pointer dereference.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=578057" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=578057</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/31/1" source="MLIST" patch="1">[oss-security] 20100331 Re: CVE request: kernel: tipc: Fix oops on send prior to entering networked mode</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/30/1" source="MLIST" patch="1">[oss-security] 20100330 CVE request: kernel: tipc: Fix oops on send prior to entering networked mode</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git;a=commitdiff;h=d0021b252eaf65ca07ed14f0d66425dd9ccab9a6;hp=6d55cb91a0020ac0d78edcad61efd6c8cf5785a3" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/davem/net-2.6.git;a=commitdiff;h=d0021b252eaf65ca07ed14f0d66425dd9ccab9a6;hp=6d55cb91a0020ac0d78edcad61efd6c8cf5785a3</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39120" source="BID">39120</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA" adv="1">43315</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA" adv="1">39830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9832" source="OVAL">oval:org.mitre.oval:def:9832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.32" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.38" />
        <vers num="2.6.27.39" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.40" />
        <vers num="2.6.27.41" />
        <vers num="2.6.27.42" />
        <vers num="2.6.27.43" />
        <vers num="2.6.27.44" />
        <vers num="2.6.27.45" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.30.y" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.12" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1188" published="2010-03-31" name="CVE-2010-1188" modified="2011-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://git.kernel.org/linus/fb7e2399ec17f1004c0e0ccfd17439f8759ede01" source="CONFIRM" patch="1">http://git.kernel.org/linus/fb7e2399ec17f1004c0e0ccfd17439f8759ede01</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0009.html</ref>
      <ref url="http://www.securitytracker.com/id?1023992" source="SECTRACK">1023992</ref>
      <ref url="http://www.securityfocus.com/bid/39016" source="BID">39016</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0882.html" source="REDHAT">RHSA-2010:0882</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0439.html" source="REDHAT">RHSA-2010:0439</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0424.html" source="REDHAT">RHSA-2010:0424</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0394.html" source="REDHAT">RHSA-2010:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0380.html" source="REDHAT">RHSA-2010:0380</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/29/1" source="MLIST">[oss-security] 20100329 CVE request: kernel: ipv6: skb is unexpectedly freed (remote DoS)</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.20</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100090459" source="CONFIRM">http://support.avaya.com/css/P8/documents/100090459</ref>
      <ref url="http://secunia.com/advisories/39652" source="SECUNIA">39652</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9878" source="OVAL">oval:org.mitre.oval:def:9878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1189" published="2010-03-31" name="CVE-2010-1189" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html" source="MLIST" patch="1" adv="1">[MediaWiki-announce] 20100303 MediaWiki security update: 1.15.2</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0685" source="VUPEN" adv="1">ADV-2010-0685</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2022" source="DEBIAN">DSA-2022</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39022" source="SECUNIA" adv="1">39022</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0" />
        <vers num="1.10.0" edition="rc1" />
        <vers num="1.10.0" edition="rc2" />
        <vers num="1.10.1" />
        <vers num="1.10.2" />
        <vers num="1.10.3" />
        <vers num="1.10.4" />
        <vers num="1.11" edition="rc1" />
        <vers num="1.11.0" edition="rc1" />
        <vers num="1.11.1" />
        <vers num="1.11.2" />
        <vers num="1.12.0" edition="rc1" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.3" />
        <vers num="1.12.4" />
        <vers num="1.13.0" edition="rc1" />
        <vers num="1.13.0" edition="rc2" />
        <vers num="1.13.1" />
        <vers num="1.13.2" />
        <vers num="1.13.3" />
        <vers num="1.13.4" />
        <vers num="1.14.0" />
        <vers num="1.15.0" />
        <vers prev="1" num="1.15.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4" edition="beta3" />
        <vers num="1.4" edition="beta4" />
        <vers num="1.4" edition="beta5" />
        <vers num="1.4" edition="beta6" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5" edition="alpha1" />
        <vers num="1.5" edition="alpha2" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5" edition="beta3" />
        <vers num="1.5" edition="beta4" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5" edition="rc3" />
        <vers num="1.5" edition="rc4" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1190" published="2010-03-31" name="CVE-2010-1190" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-March/000088.html" source="MLIST" patch="1" adv="1">[MediaWiki-announce] 20100303 MediaWiki security update: 1.15.2</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0685" source="VUPEN" adv="1">ADV-2010-0685</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2022" source="DEBIAN">DSA-2022</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES" source="CONFIRM">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_15_2/phase3/RELEASE-NOTES</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39022" source="SECUNIA" adv="1">39022</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0" />
        <vers num="1.10.0" edition="rc1" />
        <vers num="1.10.0" edition="rc2" />
        <vers num="1.10.1" />
        <vers num="1.10.2" />
        <vers num="1.10.3" />
        <vers num="1.10.4" />
        <vers num="1.11" edition="rc1" />
        <vers num="1.11.0" edition="rc1" />
        <vers num="1.11.1" />
        <vers num="1.11.2" />
        <vers num="1.12.0" edition="rc1" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.3" />
        <vers num="1.12.4" />
        <vers num="1.13.0" edition="rc1" />
        <vers num="1.13.0" edition="rc2" />
        <vers num="1.13.1" />
        <vers num="1.13.2" />
        <vers num="1.13.3" />
        <vers num="1.13.4" />
        <vers num="1.14.0" />
        <vers num="1.15.0" />
        <vers prev="1" num="1.15.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4" edition="beta3" />
        <vers num="1.4" edition="beta4" />
        <vers num="1.4" edition="beta5" />
        <vers num="1.4" edition="beta6" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.5" edition="alpha1" />
        <vers num="1.5" edition="alpha2" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5" edition="beta3" />
        <vers num="1.5" edition="beta4" />
        <vers num="1.5" edition="rc2" />
        <vers num="1.5" edition="rc3" />
        <vers num="1.5" edition="rc4" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1191" published="2010-03-31" name="CVE-2010-1191" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510164/100/0/threaded" source="BUGTRAQ">20100317 Sahana 0.6.2.2 Authentication Bypass</ref>
      <ref url="http://sourceforge.net/tracker/?func=detail&amp;aid=2970786&amp;group_id=127855&amp;atid=709778" source="MISC">http://sourceforge.net/tracker/?func=detail&amp;aid=2970786&amp;group_id=127855&amp;atid=709778</ref>
      <ref url="http://secunia.com/advisories/39020" source="SECUNIA" adv="1">39020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sahanafoundation" name="sahana">
        <vers num="0.6.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1192" published="2010-03-31" name="CVE-2010-1192" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/09/3" source="MLIST">[oss-security] 20100309 Re: CVE Request: libesmtp does not check NULL bytes in commonName</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/03/6" source="MLIST">[oss-security] 20100303 CVE Request: libesmtp does not check NULL bytes in commonName</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stafford.uklinux" name="libesmtp">
        <vers num="0.1" edition="-" />
        <vers num="0.1" edition="a" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" edition="a" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.10" edition="p1" />
        <vers num="0.8.11" />
        <vers num="0.8.12" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1193" published="2010-04-01" name="CVE-2010-1193" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0005.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0005.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000086.html" source="MLIST" patch="1" adv="1">[security-announce] 20100329 VMSA-2010-0005 VMware products address vulnerabilities in WebAccess</ref>
      <ref url="http://www.securitytracker.com/id?1023769" source="SECTRACK">1023769</ref>
      <ref url="http://www.securityfocus.com/bid/39037" source="BID">39037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1194" published="2010-03-31" name="CVE-2010-1194" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=311191" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=311191</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/09/3" source="MLIST">[oss-security] 20100309 Re: CVE Request: libesmtp does not check NULL bytes in commonName</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/03/03/6" source="MLIST">[oss-security] 20100303 CVE Request: libesmtp does not check NULL bytes in commonName</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stafford.uklinux" name="libesmtp">
        <vers num="0.1" edition="-" />
        <vers num="0.1" edition="a" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" edition="a" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.10" edition="p1" />
        <vers num="0.8.11" />
        <vers num="0.8.12" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="r1" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1195" published="2010-03-31" name="CVE-2010-1195" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0662" source="VUPEN" adv="1">ADV-2010-0662</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2020" source="DEBIAN">DSA-2020</ref>
      <ref url="http://secunia.com/advisories/39048" source="SECUNIA" adv="1">39048</ref>
      <ref url="http://secunia.com/advisories/38983" source="SECUNIA" adv="1">38983</ref>
      <ref url="http://ikiwiki.info/security/#index36h2" source="CONFIRM" adv="1">http://ikiwiki.info/security/#index36h2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ikiwiki" name="ikiwiki">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.12" />
        <vers num="2.13" />
        <vers num="2.14" />
        <vers num="2.15" />
        <vers num="2.16" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.19" />
        <vers num="2.2" />
        <vers num="2.20" />
        <vers num="2.3" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.31.1" />
        <vers num="2.31.2" />
        <vers num="2.31.3" />
        <vers num="2.4" />
        <vers num="2.40" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.43" />
        <vers num="2.44" />
        <vers num="2.45" />
        <vers num="2.46" />
        <vers num="2.47" />
        <vers num="2.48" />
        <vers num="2.49" />
        <vers num="2.5" />
        <vers num="2.50" />
        <vers num="2.51" />
        <vers num="2.52" />
        <vers num="2.53" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers num="3.02" />
        <vers num="3.03" />
        <vers num="3.04" />
        <vers num="3.05" />
        <vers num="3.06" />
        <vers num="3.07" />
        <vers num="3.08" />
        <vers num="3.09" />
        <vers num="3.10" />
        <vers num="3.11" />
        <vers num="3.12" />
        <vers num="3.13" />
        <vers num="3.14" />
        <vers num="3.141" />
        <vers num="3.1415" />
        <vers num="3.14159" />
        <vers num="3.141592" />
        <vers num="3.1415926" />
        <vers num="3.14159265" />
        <vers num="3.20091009" />
        <vers num="3.20091017" />
        <vers num="3.20091022" />
        <vers num="3.20091023" />
        <vers num="3.20091031" />
        <vers num="3.20091113" />
        <vers num="3.20091202" />
        <vers num="3.20091218" />
        <vers num="3.20100102.3" />
        <vers num="3.20100122" />
        <vers num="3.20100212" />
        <vers num="3.20100302" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1196" published="2010-06-24" name="CVE-2010-1196" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=534666" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=534666</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59665" source="XF">firefox-nsgenericdomdatanode-bo(59665)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41087" source="BID">41087</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-29.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-29.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14017" source="OVAL">oval:org.mitre.oval:def:14017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11424" source="OVAL">oval:org.mitre.oval:def:11424</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1197" published="2010-06-24" name="CVE-2010-1197" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=537120" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=537120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59667" source="XF">firefox-contentdisposition-security-bypass(59667)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1556" source="VUPEN">ADV-2010-1556</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41103" source="BID">41103</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0499.html" source="REDHAT">RHSA-2010:0499</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-32.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-32.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14186" source="OVAL">oval:org.mitre.oval:def:14186</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10168" source="OVAL">oval:org.mitre.oval:def:10168</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1198" published="2010-06-24" name="CVE-2010-1198" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=532246" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=532246</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59664" source="XF">firefox-plugin-instances-code-exec(59664)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1556" source="VUPEN">ADV-2010-1556</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41102" source="BID">41102</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0499.html" source="REDHAT">RHSA-2010:0499</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-28.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-28.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14176" source="OVAL">oval:org.mitre.oval:def:14176</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10990" source="OVAL">oval:org.mitre.oval:def:10990</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1199" published="2010-06-24" name="CVE-2010-1199" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=554255" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=554255</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59666" source="XF">firefox-xslt-node-code-execution(59666)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1556" source="VUPEN">ADV-2010-1556</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41082" source="BID">41082</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0499.html" source="REDHAT">RHSA-2010:0499</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-30.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://www.exploit-db.com/exploits/14949" source="EXPLOIT-DB">14949</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13287" source="OVAL">oval:org.mitre.oval:def:13287</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10885" source="OVAL">oval:org.mitre.oval:def:10885</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1200" published="2010-06-24" name="CVE-2010-1200" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=553938" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=553938</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=551661" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=551661</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=551233" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=551233</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=534768" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=534768</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=531176" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=531176</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=509839" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=509839</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=484890" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=484890</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59659" source="XF">firefox-seamonkey-browser-code-exec(59659)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1556" source="VUPEN">ADV-2010-1556</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41090" source="BID">41090</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0499.html" source="REDHAT">RHSA-2010:0499</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-26.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-26.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14326" source="OVAL">oval:org.mitre.oval:def:14326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10816" source="OVAL">oval:org.mitre.oval:def:10816</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1201" published="2010-06-24" name="CVE-2010-1201" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=524921" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=524921</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-26.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-26.html</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12671" source="OVAL">oval:org.mitre.oval:def:12671</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1202" published="2010-06-24" name="CVE-2010-1202" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=561592" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=561592</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=561031" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=561031</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=526449" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=526449</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=424558" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=424558</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59661" source="XF">firefox-javascript-ce(59661)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41094" source="BID">41094</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-26.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-26.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14308" source="OVAL">oval:org.mitre.oval:def:14308</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10889" source="OVAL">oval:org.mitre.oval:def:10889</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers prev="1" num="2.0.4" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.2" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1203" published="2010-06-24" name="CVE-2010-1203" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=557946" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=557946</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=546611" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=546611</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59662" source="XF">mozilla-firefox-javascript-ce(59662)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1773" source="VUPEN" adv="1">ADV-2010-1773</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1640" source="VUPEN" adv="1">ADV-2010-1640</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1557" source="VUPEN" adv="1">ADV-2010-1557</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1551" source="VUPEN" adv="1">ADV-2010-1551</ref>
      <ref url="http://www.ubuntu.com/usn/usn-930-2" source="UBUNTU">USN-930-2</ref>
      <ref url="http://www.securitytracker.com/id?1024139" source="SECTRACK">1024139</ref>
      <ref url="http://www.securitytracker.com/id?1024138" source="SECTRACK">1024138</ref>
      <ref url="http://www.securityfocus.com/bid/41099" source="BID">41099</ref>
      <ref url="http://www.securityfocus.com/bid/41050" source="BID">41050</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0501.html" source="REDHAT">RHSA-2010:0501</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0500.html" source="REDHAT">RHSA-2010:0500</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-26.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-26.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:125" source="MANDRIVA">MDVSA-2010:125</ref>
      <ref url="http://ubuntu.com/usn/usn-930-1" source="UBUNTU">USN-930-1</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100091069" source="CONFIRM">http://support.avaya.com/css/P8/documents/100091069</ref>
      <ref url="http://secunia.com/advisories/40481" source="SECUNIA" adv="1">40481</ref>
      <ref url="http://secunia.com/advisories/40401" source="SECUNIA" adv="1">40401</ref>
      <ref url="http://secunia.com/advisories/40326" source="SECUNIA" adv="1">40326</ref>
      <ref url="http://secunia.com/advisories/40323" source="SECUNIA" adv="1">40323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8317" source="OVAL">oval:org.mitre.oval:def:8317</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10401" source="OVAL">oval:org.mitre.oval:def:10401</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.html" source="SUSE">SUSE-SA:2010:030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1204" published="2010-06-28" name="CVE-2010-1204" modified="2010-06-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=309952" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=309952</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1595" source="VUPEN" adv="1">ADV-2010-1595</ref>
      <ref url="http://www.securityfocus.com/bid/41141" source="BID">41141</ref>
      <ref url="http://www.bugzilla.org/security/3.2.6/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.2.6/</ref>
      <ref url="http://secunia.com/advisories/40300" source="SECUNIA" adv="1">40300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.3.1" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.6" />
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1205" published="2010-06-30" name="CVE-2010-1205" modified="2011-08-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=608238" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=608238</ref>
      <ref url="http://www.securityfocus.com/bid/41174" source="BID" patch="1">41174</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=570451" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=570451</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=40798" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=40798</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59815" source="XF">libpng-rowdata-bo(59815)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3045" source="VUPEN">ADV-2010-3045</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2491" source="VUPEN">ADV-2010-2491</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1877" source="VUPEN">ADV-2010-1877</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1846" source="VUPEN">ADV-2010-1846</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1837" source="VUPEN">ADV-2010-1837</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1755" source="VUPEN">ADV-2010-1755</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1612" source="VUPEN" adv="1">ADV-2010-1612</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0014.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0014.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-960-1" source="UBUNTU">USN-960-1</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-41.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-41.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:133" source="MANDRIVA">MDVSA-2010:133</ref>
      <ref url="http://www.libpng.org/pub/png/libpng.html" source="CONFIRM">http://www.libpng.org/pub/png/libpng.html</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2072" source="DEBIAN">DSA-2072</ref>
      <ref url="http://trac.webkit.org/changeset/61816" source="CONFIRM">http://trac.webkit.org/changeset/61816</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://support.apple.com/kb/HT4457" source="CONFIRM">http://support.apple.com/kb/HT4457</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://secunia.com/advisories/42317" source="SECUNIA">42317</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41574" source="SECUNIA">41574</ref>
      <ref url="http://secunia.com/advisories/40547" source="SECUNIA">40547</ref>
      <ref url="http://secunia.com/advisories/40472" source="SECUNIA">40472</ref>
      <ref url="http://secunia.com/advisories/40302" source="SECUNIA" adv="1">40302</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11851" source="OVAL">oval:org.mitre.oval:def:11851</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000105.html" source="MLIST">[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044397.html" source="FEDORA">FEDORA-2010-10833</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044283.html" source="FEDORA">FEDORA-2010-10823</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=188eb6b42602bf7d7ae708a21897923b6a83fe7c#patch18" source="CONFIRM">http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng;a=commitdiff;h=188eb6b42602bf7d7ae708a21897923b6a83fe7c#patch18</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=45983" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=45983</ref>
      <ref url="http://blackberry.com/btsc/KB27244" source="CONFIRM">http://blackberry.com/btsc/KB27244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libpng" name="libpng">
        <vers num="0.89c" />
        <vers num="0.95" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" edition="beta1" />
        <vers num="1.0.10" edition="rc1" />
        <vers num="1.0.11" edition="beta1" />
        <vers num="1.0.11" edition="beta2" />
        <vers num="1.0.11" edition="beta3" />
        <vers num="1.0.11" edition="rc1" />
        <vers num="1.0.12" edition="beta1" />
        <vers num="1.0.12" edition="rc1" />
        <vers num="1.0.13" />
        <vers num="1.0.14" />
        <vers num="1.0.15" edition="rc1" />
        <vers num="1.0.15" edition="rc2" />
        <vers num="1.0.15" edition="rc3" />
        <vers num="1.0.16" />
        <vers num="1.0.17" edition="rc1" />
        <vers num="1.0.18" />
        <vers num="1.0.19" edition="rc1" />
        <vers num="1.0.19" edition="rc2" />
        <vers num="1.0.19" edition="rc3" />
        <vers num="1.0.19" edition="rc5" />
        <vers num="1.0.2" />
        <vers num="1.0.20" />
        <vers num="1.0.21" edition="rc1" />
        <vers num="1.0.21" edition="rc2" />
        <vers num="1.0.22" edition="rc1" />
        <vers num="1.0.23" edition="rc1" />
        <vers num="1.0.23" edition="rc2" />
        <vers num="1.0.23" edition="rc3" />
        <vers num="1.0.23" edition="rc4" />
        <vers num="1.0.23" edition="rc5" />
        <vers num="1.0.24" edition="rc1" />
        <vers num="1.0.25" edition="rc1" />
        <vers num="1.0.25" edition="rc2" />
        <vers num="1.0.26" />
        <vers num="1.0.27" edition="rc1" />
        <vers num="1.0.27" edition="rc2" />
        <vers num="1.0.27" edition="rc3" />
        <vers num="1.0.27" edition="rc4" />
        <vers num="1.0.27" edition="rc5" />
        <vers num="1.0.27" edition="rc6" />
        <vers num="1.0.28" edition="rc2" />
        <vers num="1.0.28" edition="rc3" />
        <vers num="1.0.28" edition="rc4" />
        <vers num="1.0.28" edition="rc5" />
        <vers num="1.0.28" edition="rc6" />
        <vers num="1.0.29" edition="beta1" />
        <vers num="1.0.29" edition="rc1" />
        <vers num="1.0.29" edition="rc2" />
        <vers num="1.0.29" edition="rc3" />
        <vers num="1.0.3" />
        <vers num="1.0.30" edition="rc1" />
        <vers num="1.0.31" edition="rc01" />
        <vers num="1.0.32" />
        <vers num="1.0.33" />
        <vers num="1.0.34" />
        <vers num="1.0.35" />
        <vers num="1.0.37" />
        <vers num="1.0.38" />
        <vers num="1.0.39" />
        <vers num="1.0.40" />
        <vers num="1.0.41" />
        <vers num="1.0.42" />
        <vers num="1.0.43" />
        <vers num="1.0.44" />
        <vers num="1.0.45" />
        <vers num="1.0.46" />
        <vers num="1.0.47" />
        <vers num="1.0.48" />
        <vers num="1.0.5" />
        <vers num="1.0.50" />
        <vers num="1.0.51" />
        <vers num="1.0.52" />
        <vers num="1.0.53" />
        <vers num="1.0.6" edition="a" />
        <vers num="1.0.6" edition="d" />
        <vers num="1.0.6" edition="e" />
        <vers num="1.0.6" edition="f" />
        <vers num="1.0.6" edition="g" />
        <vers num="1.0.6" edition="h" />
        <vers num="1.0.6" edition="i" />
        <vers num="1.0.6" edition="j" />
        <vers num="1.0.7" edition="beta11" />
        <vers num="1.0.7" edition="beta12" />
        <vers num="1.0.7" edition="beta13" />
        <vers num="1.0.7" edition="beta14" />
        <vers num="1.0.7" edition="beta15" />
        <vers num="1.0.7" edition="beta16" />
        <vers num="1.0.7" edition="beta17" />
        <vers num="1.0.7" edition="beta18" />
        <vers num="1.0.7" edition="rc1" />
        <vers num="1.0.7" edition="rc2" />
        <vers num="1.0.8" edition="beta1" />
        <vers num="1.0.8" edition="beta2" />
        <vers num="1.0.8" edition="beta3" />
        <vers num="1.0.8" edition="beta4" />
        <vers num="1.0.8" edition="rc1" />
        <vers num="1.0.9" edition="beta1" />
        <vers num="1.0.9" edition="beta10" />
        <vers num="1.0.9" edition="beta2" />
        <vers num="1.0.9" edition="beta3" />
        <vers num="1.0.9" edition="beta4" />
        <vers num="1.0.9" edition="beta5" />
        <vers num="1.0.9" edition="beta6" />
        <vers num="1.0.9" edition="beta7" />
        <vers num="1.0.9" edition="beta8" />
        <vers num="1.0.9" edition="beta9" />
        <vers num="1.0.9" edition="rc1" />
        <vers num="1.0.9" edition="rc2" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="beta5" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" edition="beta1" />
        <vers num="1.2.1" edition="beta2" />
        <vers num="1.2.1" edition="beta3" />
        <vers num="1.2.1" edition="beta4" />
        <vers num="1.2.1" edition="rc1" />
        <vers num="1.2.1" edition="rc2" />
        <vers num="1.2.10" edition="beta1" />
        <vers num="1.2.10" edition="beta2" />
        <vers num="1.2.10" edition="beta3" />
        <vers num="1.2.10" edition="beta4" />
        <vers num="1.2.10" edition="beta5" />
        <vers num="1.2.10" edition="beta6" />
        <vers num="1.2.10" edition="beta7" />
        <vers num="1.2.10" edition="rc1" />
        <vers num="1.2.10" edition="rc2" />
        <vers num="1.2.10" edition="rc3" />
        <vers num="1.2.11" edition="beta1" />
        <vers num="1.2.11" edition="beta2" />
        <vers num="1.2.11" edition="beta3" />
        <vers num="1.2.11" edition="beta4" />
        <vers num="1.2.11" edition="rc1" />
        <vers num="1.2.11" edition="rc2" />
        <vers num="1.2.11" edition="rc3" />
        <vers num="1.2.11" edition="rc5" />
        <vers num="1.2.13" edition="beta1" />
        <vers num="1.2.13" edition="rc1" />
        <vers num="1.2.13" edition="rc2" />
        <vers num="1.2.14" edition="beta1" />
        <vers num="1.2.14" edition="beta2" />
        <vers num="1.2.14" edition="rc1" />
        <vers num="1.2.15" edition="beta1" />
        <vers num="1.2.15" edition="beta2" />
        <vers num="1.2.15" edition="beta3" />
        <vers num="1.2.15" edition="beta4" />
        <vers num="1.2.15" edition="beta5" />
        <vers num="1.2.15" edition="beta6" />
        <vers num="1.2.15" edition="rc1" />
        <vers num="1.2.15" edition="rc2" />
        <vers num="1.2.15" edition="rc3" />
        <vers num="1.2.15" edition="rc4" />
        <vers num="1.2.15" edition="rc5" />
        <vers num="1.2.16" edition="beta1" />
        <vers num="1.2.16" edition="beta2" />
        <vers num="1.2.16" edition="rc1" />
        <vers num="1.2.17" edition="beta1" />
        <vers num="1.2.17" edition="beta2" />
        <vers num="1.2.17" edition="rc1" />
        <vers num="1.2.17" edition="rc2" />
        <vers num="1.2.17" edition="rc3" />
        <vers num="1.2.17" edition="rc4" />
        <vers num="1.2.18" />
        <vers num="1.2.19" edition="beta1" />
        <vers num="1.2.19" edition="beta10" />
        <vers num="1.2.19" edition="beta11" />
        <vers num="1.2.19" edition="beta12" />
        <vers num="1.2.19" edition="beta13" />
        <vers num="1.2.19" edition="beta14" />
        <vers num="1.2.19" edition="beta15" />
        <vers num="1.2.19" edition="beta16" />
        <vers num="1.2.19" edition="beta17" />
        <vers num="1.2.19" edition="beta18" />
        <vers num="1.2.19" edition="beta19" />
        <vers num="1.2.19" edition="beta2" />
        <vers num="1.2.19" edition="beta20" />
        <vers num="1.2.19" edition="beta21" />
        <vers num="1.2.19" edition="beta22" />
        <vers num="1.2.19" edition="beta23" />
        <vers num="1.2.19" edition="beta24" />
        <vers num="1.2.19" edition="beta25" />
        <vers num="1.2.19" edition="beta26" />
        <vers num="1.2.19" edition="beta27" />
        <vers num="1.2.19" edition="beta28" />
        <vers num="1.2.19" edition="beta29" />
        <vers num="1.2.19" edition="beta3" />
        <vers num="1.2.19" edition="beta30" />
        <vers num="1.2.19" edition="beta31" />
        <vers num="1.2.19" edition="beta32" />
        <vers num="1.2.19" edition="beta33" />
        <vers num="1.2.19" edition="beta4" />
        <vers num="1.2.19" edition="beta5" />
        <vers num="1.2.19" edition="beta6" />
        <vers num="1.2.19" edition="beta7" />
        <vers num="1.2.19" edition="beta8" />
        <vers num="1.2.19" edition="beta9" />
        <vers num="1.2.19" edition="rc1" />
        <vers num="1.2.19" edition="rc2" />
        <vers num="1.2.19" edition="rc3" />
        <vers num="1.2.19" edition="rc4" />
        <vers num="1.2.19" edition="rc5" />
        <vers num="1.2.19" edition="rc6" />
        <vers num="1.2.2" edition="beta1" />
        <vers num="1.2.2" edition="beta2" />
        <vers num="1.2.2" edition="beta3" />
        <vers num="1.2.2" edition="beta4" />
        <vers num="1.2.2" edition="beta5" />
        <vers num="1.2.2" edition="beta6" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.20" edition="beta01" />
        <vers num="1.2.20" edition="beta02" />
        <vers num="1.2.20" edition="beta03" />
        <vers num="1.2.20" edition="beta04" />
        <vers num="1.2.20" edition="rc1" />
        <vers num="1.2.20" edition="rc2" />
        <vers num="1.2.20" edition="rc3" />
        <vers num="1.2.20" edition="rc4" />
        <vers num="1.2.20" edition="rc5" />
        <vers num="1.2.20" edition="rc6" />
        <vers num="1.2.21" edition="beta1" />
        <vers num="1.2.21" edition="beta2" />
        <vers num="1.2.21" edition="rc1" />
        <vers num="1.2.21" edition="rc2" />
        <vers num="1.2.21" edition="rc3" />
        <vers num="1.2.22" edition="beta1" />
        <vers num="1.2.22" edition="beta2" />
        <vers num="1.2.22" edition="beta2-1.2.21" />
        <vers num="1.2.22" edition="beta3" />
        <vers num="1.2.22" edition="beta3-1.2.21" />
        <vers num="1.2.22" edition="beta4" />
        <vers num="1.2.22" edition="beta4-1.2.21" />
        <vers num="1.2.22" edition="rc1" />
        <vers num="1.2.22" edition="rc1-1.2.21" />
        <vers num="1.2.23" edition="beta01" />
        <vers num="1.2.23" edition="beta01-1.2.22" />
        <vers num="1.2.23" edition="beta02" />
        <vers num="1.2.23" edition="beta02-1.2.22" />
        <vers num="1.2.23" edition="beta03" />
        <vers num="1.2.23" edition="beta03-1.2.22" />
        <vers num="1.2.23" edition="beta04" />
        <vers num="1.2.23" edition="beta04-1.2.22" />
        <vers num="1.2.23" edition="beta05" />
        <vers num="1.2.23" edition="beta05-1.2.22" />
        <vers num="1.2.23" edition="rc01" />
        <vers num="1.2.23" edition="rc01-1.2.22" />
        <vers num="1.2.24" edition="beta01" />
        <vers num="1.2.24" edition="beta01-1.2.23" />
        <vers num="1.2.24" edition="beta02" />
        <vers num="1.2.24" edition="beta02-1.2.23" />
        <vers num="1.2.24" edition="beta03" />
        <vers num="1.2.24" edition="beta03-1.2.23" />
        <vers num="1.2.24" edition="rc01" />
        <vers num="1.2.24" edition="rc01-1.2.23" />
        <vers num="1.2.25" edition="beta01" />
        <vers num="1.2.25" edition="beta02" />
        <vers num="1.2.25" edition="beta03" />
        <vers num="1.2.25" edition="beta04" />
        <vers num="1.2.25" edition="beta05" />
        <vers num="1.2.25" edition="beta06" />
        <vers num="1.2.25" edition="rc01" />
        <vers num="1.2.25" edition="rc02" />
        <vers num="1.2.26" edition="beta01" />
        <vers num="1.2.26" edition="beta02" />
        <vers num="1.2.26" edition="beta03" />
        <vers num="1.2.26" edition="beta04" />
        <vers num="1.2.26" edition="beta05" />
        <vers num="1.2.26" edition="beta06" />
        <vers num="1.2.26" edition="rc01" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.3" edition="rc1" />
        <vers num="1.2.3" edition="rc2" />
        <vers num="1.2.3" edition="rc3" />
        <vers num="1.2.3" edition="rc4" />
        <vers num="1.2.3" edition="rc5" />
        <vers num="1.2.3" edition="rc6" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
        <vers num="1.2.32" />
        <vers num="1.2.33" />
        <vers num="1.2.34" />
        <vers num="1.2.35" />
        <vers num="1.2.36" />
        <vers num="1.2.37" edition="beta1" />
        <vers num="1.2.37" edition="beta2" />
        <vers num="1.2.37" edition="beta3" />
        <vers num="1.2.37" edition="rc1" />
        <vers num="1.2.38" edition="beta1" />
        <vers num="1.2.38" edition="rc1" />
        <vers num="1.2.38" edition="rc2" />
        <vers num="1.2.38" edition="rc3" />
        <vers num="1.2.39" edition="beta1" />
        <vers num="1.2.39" edition="beta2" />
        <vers num="1.2.39" edition="beta3" />
        <vers num="1.2.39" edition="beta4" />
        <vers num="1.2.39" edition="beta5" />
        <vers num="1.2.39" edition="rc1" />
        <vers num="1.2.4" edition="beta1" />
        <vers num="1.2.4" edition="beta2" />
        <vers num="1.2.4" edition="beta3" />
        <vers num="1.2.4" edition="rc1" />
        <vers num="1.2.40" edition="beta1" />
        <vers num="1.2.40" edition="rc1" />
        <vers num="1.2.41" edition="beta1" />
        <vers num="1.2.41" edition="beta11" />
        <vers num="1.2.41" edition="beta12" />
        <vers num="1.2.41" edition="beta13" />
        <vers num="1.2.41" edition="beta14" />
        <vers num="1.2.41" edition="beta16" />
        <vers num="1.2.41" edition="beta17" />
        <vers num="1.2.41" edition="beta18" />
        <vers num="1.2.41" edition="beta2" />
        <vers num="1.2.41" edition="beta3" />
        <vers num="1.2.41" edition="beta4" />
        <vers num="1.2.41" edition="beta5" />
        <vers num="1.2.41" edition="beta6" />
        <vers num="1.2.41" edition="beta7" />
        <vers num="1.2.41" edition="beta8" />
        <vers num="1.2.41" edition="beta9" />
        <vers num="1.2.41" edition="rc1" />
        <vers num="1.2.41" edition="rc2" />
        <vers num="1.2.41" edition="rc3" />
        <vers num="1.2.42" edition="beta1" />
        <vers num="1.2.42" edition="beta2" />
        <vers num="1.2.42" edition="rc1" />
        <vers num="1.2.42" edition="rc2" />
        <vers num="1.2.42" edition="rc3" />
        <vers num="1.2.42" edition="rc4" />
        <vers num="1.2.42" edition="rc5" />
        <vers prev="1" num="1.2.43" />
        <vers num="1.2.5" edition="beta1" />
        <vers num="1.2.5" edition="beta2" />
        <vers num="1.2.5" edition="beta3" />
        <vers num="1.2.5" edition="rc1" />
        <vers num="1.2.5" edition="rc2" />
        <vers num="1.2.5" edition="rc3" />
        <vers num="1.2.6" edition="beta1" />
        <vers num="1.2.6" edition="beta2" />
        <vers num="1.2.6" edition="beta3" />
        <vers num="1.2.6" edition="beta4" />
        <vers num="1.2.6" edition="rc1" />
        <vers num="1.2.6" edition="rc2" />
        <vers num="1.2.6" edition="rc3" />
        <vers num="1.2.6" edition="rc4" />
        <vers num="1.2.6" edition="rc5" />
        <vers num="1.2.7" edition="beta1" />
        <vers num="1.2.7" edition="beta2" />
        <vers num="1.2.8" edition="beta1" />
        <vers num="1.2.8" edition="beta2" />
        <vers num="1.2.8" edition="beta3" />
        <vers num="1.2.8" edition="beta4" />
        <vers num="1.2.8" edition="beta5" />
        <vers num="1.2.8" edition="rc1" />
        <vers num="1.2.8" edition="rc2" />
        <vers num="1.2.8" edition="rc3" />
        <vers num="1.2.8" edition="rc4" />
        <vers num="1.2.8" edition="rc5" />
        <vers num="1.2.9" edition="beta1" />
        <vers num="1.2.9" edition="beta10" />
        <vers num="1.2.9" edition="beta2" />
        <vers num="1.2.9" edition="beta3" />
        <vers num="1.2.9" edition="beta4" />
        <vers num="1.2.9" edition="beta5" />
        <vers num="1.2.9" edition="beta6" />
        <vers num="1.2.9" edition="beta7" />
        <vers num="1.2.9" edition="beta8" />
        <vers num="1.2.9" edition="beta9" />
        <vers num="1.2.9" edition="rc1" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta10" />
        <vers num="1.4" edition="beta11" />
        <vers num="1.4" edition="beta12" />
        <vers num="1.4" edition="beta13" />
        <vers num="1.4" edition="beta14" />
        <vers num="1.4" edition="beta15" />
        <vers num="1.4" edition="beta16" />
        <vers num="1.4" edition="beta17" />
        <vers num="1.4" edition="beta18" />
        <vers num="1.4" edition="beta19" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4" edition="beta20" />
        <vers num="1.4" edition="beta22" />
        <vers num="1.4" edition="beta23" />
        <vers num="1.4" edition="beta24" />
        <vers num="1.4" edition="beta25" />
        <vers num="1.4" edition="beta26" />
        <vers num="1.4" edition="beta27" />
        <vers num="1.4" edition="beta28" />
        <vers num="1.4" edition="beta29" />
        <vers num="1.4" edition="beta3" />
        <vers num="1.4" edition="beta30" />
        <vers num="1.4" edition="beta31" />
        <vers num="1.4" edition="beta33" />
        <vers num="1.4" edition="beta4" />
        <vers num="1.4" edition="beta5" />
        <vers num="1.4" edition="beta6" />
        <vers num="1.4" edition="beta7" />
        <vers num="1.4" edition="beta8" />
        <vers num="1.4" edition="beta9" />
        <vers num="1.4.0" edition="beta100" />
        <vers num="1.4.0" edition="beta101" />
        <vers num="1.4.0" edition="beta102" />
        <vers num="1.4.0" edition="beta103" />
        <vers num="1.4.0" edition="beta104" />
        <vers num="1.4.0" edition="beta105" />
        <vers num="1.4.0" edition="beta106" />
        <vers num="1.4.0" edition="beta107" />
        <vers num="1.4.0" edition="beta108" />
        <vers num="1.4.0" edition="beta109" />
        <vers num="1.4.0" edition="beta21" />
        <vers num="1.4.0" edition="beta32" />
        <vers num="1.4.0" edition="beta34" />
        <vers num="1.4.0" edition="beta35" />
        <vers num="1.4.0" edition="beta36" />
        <vers num="1.4.0" edition="beta37" />
        <vers num="1.4.0" edition="beta38" />
        <vers num="1.4.0" edition="beta39" />
        <vers num="1.4.0" edition="beta40" />
        <vers num="1.4.0" edition="beta41" />
        <vers num="1.4.0" edition="beta42" />
        <vers num="1.4.0" edition="beta43" />
        <vers num="1.4.0" edition="beta44" />
        <vers num="1.4.0" edition="beta45" />
        <vers num="1.4.0" edition="beta46" />
        <vers num="1.4.0" edition="beta47" />
        <vers num="1.4.0" edition="beta48" />
        <vers num="1.4.0" edition="beta49" />
        <vers num="1.4.0" edition="beta50" />
        <vers num="1.4.0" edition="beta51" />
        <vers num="1.4.0" edition="beta52" />
        <vers num="1.4.0" edition="beta53" />
        <vers num="1.4.0" edition="beta54" />
        <vers num="1.4.0" edition="beta55" />
        <vers num="1.4.0" edition="beta56" />
        <vers num="1.4.0" edition="beta57" />
        <vers num="1.4.0" edition="beta58" />
        <vers num="1.4.0" edition="beta59" />
        <vers num="1.4.0" edition="beta60" />
        <vers num="1.4.0" edition="beta61" />
        <vers num="1.4.0" edition="beta62" />
        <vers num="1.4.0" edition="beta63" />
        <vers num="1.4.0" edition="beta64" />
        <vers num="1.4.0" edition="beta65" />
        <vers num="1.4.0" edition="beta66" />
        <vers num="1.4.0" edition="beta67" />
        <vers num="1.4.0" edition="beta68" />
        <vers num="1.4.0" edition="beta69" />
        <vers num="1.4.0" edition="beta70" />
        <vers num="1.4.0" edition="beta71" />
        <vers num="1.4.0" edition="beta72" />
        <vers num="1.4.0" edition="beta73" />
        <vers num="1.4.0" edition="beta74" />
        <vers num="1.4.0" edition="beta75" />
        <vers num="1.4.0" edition="beta76" />
        <vers num="1.4.0" edition="beta77" />
        <vers num="1.4.0" edition="beta78" />
        <vers num="1.4.0" edition="beta79" />
        <vers num="1.4.0" edition="beta80" />
        <vers num="1.4.0" edition="beta81" />
        <vers num="1.4.0" edition="beta82" />
        <vers num="1.4.0" edition="beta83" />
        <vers num="1.4.0" edition="beta84" />
        <vers num="1.4.0" edition="beta85" />
        <vers num="1.4.0" edition="beta86" />
        <vers num="1.4.0" edition="beta87" />
        <vers num="1.4.0" edition="beta88" />
        <vers num="1.4.0" edition="beta89" />
        <vers num="1.4.0" edition="beta90" />
        <vers num="1.4.0" edition="beta91" />
        <vers num="1.4.0" edition="beta92" />
        <vers num="1.4.0" edition="beta93" />
        <vers num="1.4.0" edition="beta94" />
        <vers num="1.4.0" edition="beta95" />
        <vers num="1.4.0" edition="beta96" />
        <vers num="1.4.0" edition="beta97" />
        <vers num="1.4.0" edition="beta98" />
        <vers num="1.4.0" edition="beta99" />
        <vers num="1.4.0" edition="rc01" />
        <vers num="1.4.0" edition="rc02" />
        <vers num="1.4.0" edition="rc03" />
        <vers num="1.4.0" edition="rc04" />
        <vers num="1.4.0" edition="rc05" />
        <vers num="1.4.0" edition="rc06" />
        <vers num="1.4.0" edition="rc07" />
        <vers num="1.4.0" edition="rc08" />
        <vers num="1.4.1" edition="beta01" />
        <vers num="1.4.1" edition="beta02" />
        <vers num="1.4.1" edition="beta03" />
        <vers num="1.4.1" edition="beta04" />
        <vers num="1.4.1" edition="beta05" />
        <vers num="1.4.1" edition="beta06" />
        <vers num="1.4.1" edition="beta07" />
        <vers num="1.4.1" edition="beta08" />
        <vers num="1.4.1" edition="beta09" />
        <vers num="1.4.1" edition="beta10" />
        <vers num="1.4.1" edition="beta11" />
        <vers num="1.4.1" edition="beta12" />
        <vers num="1.4.1" edition="r03" />
        <vers num="1.4.1" edition="rc01" />
        <vers num="1.4.1" edition="rc02" />
        <vers num="1.4.1" edition="rc04" />
        <vers num="1.4.2" edition="beta1" />
        <vers num="1.4.2" edition="rc01" />
        <vers num="1.4.2" edition="rc02" />
        <vers num="1.4.2" edition="rc03" />
        <vers num="1.4.2" edition="rc04" />
        <vers num="1.4.2" edition="rc05" />
        <vers num="1.4.2" edition="rc06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1206" published="2010-06-25" name="CVE-2010-1206" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=556957" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=556957</ref>
      <ref url="http://hg.mozilla.org/mozilla-central/rev/cadddabb1178" source="CONFIRM" patch="1">http://hg.mozilla.org/mozilla-central/rev/cadddabb1178</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-45.html" source="CONFIRM">http://www.mozilla.org/security/announce/2010/mfsa2010-45.html</ref>
      <ref url="http://secunia.com/advisories/40283" source="SECUNIA" adv="1">40283</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8248" source="OVAL">oval:org.mitre.oval:def:8248</ref>
      <ref url="http://lcamtuf.blogspot.com/2010/06/yeah-about-that-address-bar-thing.html" source="MISC">http://lcamtuf.blogspot.com/2010/06/yeah-about-that-address-bar-thing.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1207" published="2010-07-30" name="CVE-2010-1207" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=571287" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=571287</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-43.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-43.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11887" source="OVAL">oval:org.mitre.oval:def:11887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers prev="1" num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1208" published="2010-07-30" name="CVE-2010-1208" modified="2010-11-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=572986" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=572986</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-134/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-134/</ref>
      <ref url="http://www.securityfocus.com/bid/41849" source="BID">41849</ref>
      <ref url="http://www.securityfocus.com/archive/1/512515" source="BUGTRAQ">20100721 ZDI-10-134: Mozilla Firefox DOM Attribute Cloning Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-35.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-35.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11740" source="OVAL">oval:org.mitre.oval:def:11740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1209" published="2010-07-30" name="CVE-2010-1209" modified="2010-12-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552110" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=552110</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-130/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-130/</ref>
      <ref url="http://www.securityfocus.com/bid/41845" source="BID">41845</ref>
      <ref url="http://www.securityfocus.com/archive/1/512511" source="BUGTRAQ">20100721 ZDI-10-130: Mozilla Firefox NodeIterator Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-36.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-36.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11055" source="OVAL">oval:org.mitre.oval:def:11055</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1210" published="2010-07-30" name="CVE-2010-1210" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=564679" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=564679</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-44.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-44.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11863" source="OVAL">oval:org.mitre.oval:def:11863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" edition="beta1" />
        <vers num="3.2" edition="beta1" />
        <vers num="3.2" edition="beta2" />
        <vers num="3.2" edition="beta3" />
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers prev="1" num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.7.1" />
        <vers num="1.7.3" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1211" published="2010-07-30" name="CVE-2010-1211" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=574750" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=574750</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=570657" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=570657</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=567059" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=567059</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=566136" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=566136</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=564705" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=564705</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=561539" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=561539</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=559241" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=559241</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=535926" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=535926</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=529087" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=529087</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=528644" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=528644</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=507775" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=507775</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-34.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-34.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11552" source="OVAL">oval:org.mitre.oval:def:11552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1212" published="2010-07-30" name="CVE-2010-1212" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function, (2) depth handling in the TraceRecorder::record_JSOP_GETELEM function, and (3) tracing of out-of-range arguments in the TraceRecorder::record_JSOP_ARGSUB function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=568855" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=568855</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=558618" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=558618</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=530955" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=530955</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-34.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-34.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11771" source="OVAL">oval:org.mitre.oval:def:11771</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1213" published="2010-07-30" name="CVE-2010-1213" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=568148" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=568148</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-42.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-42.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11835" source="OVAL">oval:org.mitre.oval:def:11835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1214" published="2010-07-30" name="CVE-2010-1214" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=572985" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=572985</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-37.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-37.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11685" source="OVAL">oval:org.mitre.oval:def:11685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.9" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers prev="1" num="2.0.5" />
        <vers num="2.0a1pre" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1215" published="2010-07-30" name="CVE-2010-1215" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=567069" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=567069</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-38.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-38.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11527" source="OVAL">oval:org.mitre.oval:def:11527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1216" published="2010-03-30" name="CVE-2010-1216" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0673" source="VUPEN" adv="1">ADV-2010-0673</ref>
      <ref url="http://www.exploit-db.com/exploits/11832" source="EXPLOIT-DB">11832</ref>
      <ref url="http://secunia.com/advisories/39070" source="SECUNIA" adv="1">39070</ref>
      <ref url="http://inj3ct0r.com/exploits/11393" source="MISC">http://inj3ct0r.com/exploits/11393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="notsopureedit" name="notsopureedit">
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1217" published="2010-03-30" name="CVE-2010-1217" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38866" source="BID">38866</ref>
      <ref url="http://www.packetstormsecurity.org/1003-exploits/joomlajetooltip-lfi.txt" source="MISC">http://www.packetstormsecurity.org/1003-exploits/joomlajetooltip-lfi.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/11814" source="EXPLOIT-DB">11814</ref>
      <ref url="http://secunia.com/advisories/39063" source="SECUNIA" adv="1">39063</ref>
      <ref url="http://osvdb.org/63120" source="OSVDB">63120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="je_form_creator" name="je_form_creator">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1218" published="2010-03-30" name="CVE-2010-1218" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-007/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-007/</ref>
      <ref url="http://typo3.org/extensions/repository/view/mm_forum/1.8.3/" source="CONFIRM" patch="1">http://typo3.org/extensions/repository/view/mm_forum/1.8.3/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57037" source="XF">mmforum-unspecified-xss(57037)</ref>
      <ref url="http://www.securityfocus.com/bid/38825" source="BID">38825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mm_forum" name="mmforum">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1219" published="2010-03-30" name="CVE-2010-1219" modified="2010-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56901" source="XF">janews-index-file-include(56901)</ref>
      <ref url="http://www.securityfocus.com/bid/38746" source="BID">38746</ref>
      <ref url="http://www.exploit-db.com/exploits/11757" source="EXPLOIT-DB">11757</ref>
      <ref url="http://secunia.com/advisories/38952" source="SECUNIA" adv="1">38952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="com_janews" name="com_janews">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1221" published="2010-04-07" name="CVE-2010-1221" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.</descript>
      <descript source="nvd">Per: https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869

'The first vulnerability, CVE-2010-1221, occurs due to a lack of authentication. An attacker can make a SOAP request to enumerate user names. This vulnerability has a low risk rating and affects r12.0 and r12.5 XOsoft products.'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869" source="CONFIRM" patch="1" adv="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869</ref>
      <ref url="http://www.securityfocus.com/bid/39244" source="BID" patch="1">39244</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510564/100/0/threaded" source="BUGTRAQ">20100406 CA20100406-01: Security Notice for CA XOsoft</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="xosoft_content_distribution">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_high_availability">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_replication">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1222" published="2010-04-07" name="CVE-2010-1222" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869" source="CONFIRM" patch="1" adv="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869</ref>
      <ref url="http://www.securityfocus.com/bid/39249" source="BID" patch="1">39249</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510564/100/0/threaded" source="BUGTRAQ">20100406 CA20100406-01: Security Notice for CA XOsoft</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="xosoft_content_distribution">
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_high_availability">
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_replication">
        <vers num="r12.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1223" published="2010-04-07" name="CVE-2010-1223" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869" source="CONFIRM" patch="1" adv="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=232869</ref>
      <ref url="http://www.securityfocus.com/bid/39238" source="BID" patch="1">39238</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-066/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-066/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-065/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-065/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510567/100/0/threaded" source="BUGTRAQ">20100406 ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510565/100/0/threaded" source="BUGTRAQ">20100406 ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510564/100/0/threaded" source="BUGTRAQ">20100406 CA20100406-01: Security Notice for CA XOsoft</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="xosoft_content_distribution">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_high_availability">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
      <prod vendor="ca" name="xosoft_replication">
        <vers num="r12.0" />
        <vers num="r12.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1224" published="2010-04-01" name="CVE-2010-1224" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote attackers to bypass ACL rules and access services from unauthorized hosts.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.2.diff" source="CONFIRM" patch="1">http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.2.diff</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56552" source="XF">asterisk-cidr-security-bypass(56552)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0475" source="VUPEN" adv="1">ADV-2010-0475</ref>
      <ref url="http://www.securityfocus.com/bid/38424" source="BID">38424</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509757/100/0/threaded" source="BUGTRAQ">20100225 AST-2010-003: Invalid parsing of ACL rules can compromise security</ref>
      <ref url="http://secunia.com/advisories/39096" source="SECUNIA">39096</ref>
      <ref url="http://secunia.com/advisories/38752" source="SECUNIA" adv="1">38752</ref>
      <ref url="http://osvdb.org/62588" source="OSVDB">62588</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html" source="FEDORA">FEDORA-2010-3724</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-003.html" source="CONFIRM">http://downloads.asterisk.org/pub/security/AST-2010-003.html</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.1.diff" source="CONFIRM">http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.1.diff</ref>
      <ref url="http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.0.diff" source="CONFIRM">http://downloads.asterisk.org/pub/security/AST-2010-003-1.6.0.diff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.6.0" />
        <vers num="1.6.0.1" />
        <vers num="1.6.0.10" />
        <vers num="1.6.0.12" />
        <vers num="1.6.0.13" />
        <vers num="1.6.0.14" />
        <vers num="1.6.0.15" />
        <vers num="1.6.0.16" edition="rc1" />
        <vers num="1.6.0.16" edition="rc2" />
        <vers num="1.6.0.17" />
        <vers num="1.6.0.18" edition="rc1" />
        <vers num="1.6.0.18" edition="rc2" />
        <vers num="1.6.0.18" edition="rc3" />
        <vers num="1.6.0.19" />
        <vers num="1.6.0.2" />
        <vers num="1.6.0.20" edition="rc1" />
        <vers num="1.6.0.21" edition="rc1" />
        <vers num="1.6.0.22" />
        <vers num="1.6.0.23" edition="rc2" />
        <vers num="1.6.0.24" />
        <vers num="1.6.0.3" />
        <vers num="1.6.0.5" />
        <vers num="1.6.0.6" />
        <vers num="1.6.0.7" />
        <vers num="1.6.0.8" />
        <vers num="1.6.0.9" />
        <vers num="1.6.1" />
        <vers num="1.6.1.1" />
        <vers num="1.6.1.10" edition="rc1" />
        <vers num="1.6.1.10" edition="rc2" />
        <vers num="1.6.1.10" edition="rc3" />
        <vers num="1.6.1.11" />
        <vers num="1.6.1.12" edition="rc1" />
        <vers num="1.6.1.13" edition="rc1" />
        <vers num="1.6.1.14" />
        <vers num="1.6.1.15" edition="rc2" />
        <vers num="1.6.1.16" />
        <vers num="1.6.1.2" />
        <vers num="1.6.1.4" />
        <vers num="1.6.1.5" />
        <vers num="1.6.1.6" />
        <vers num="1.6.1.7" edition="rc1" />
        <vers num="1.6.1.7" edition="rc2" />
        <vers num="1.6.1.8" />
        <vers num="1.6.1.9" />
        <vers num="1.6.2.0" edition="rc2" />
        <vers num="1.6.2.0" edition="rc3" />
        <vers num="1.6.2.0" edition="rc4" />
        <vers num="1.6.2.0" edition="rc5" />
        <vers num="1.6.2.0" edition="rc6" />
        <vers num="1.6.2.0" edition="rc7" />
        <vers num="1.6.2.0" edition="rc8" />
        <vers num="1.6.2.1" edition="rc1" />
        <vers num="1.6.2.2" />
        <vers num="1.6.2.3" edition="rc2" />
        <vers num="1.6.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1225" published="2010-04-01" name="CVE-2010-1225" modified="2010-04-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application.  NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38764" source="BID">38764</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510154/100/0/threaded" source="BUGTRAQ">20100316 CORE-2009-0803: Virtual PC Hypervisor Memory Protection Vulnerability</ref>
      <ref url="http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug" source="MISC">http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug</ref>
      <ref url="http://securitytracker.com/id?1023720" source="SECTRACK">1023720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_pc">
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="virtual_server">
        <vers num="2005" edition="r2_sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_virtual_pc">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1226" published="2010-04-01" name="CVE-2010-1226" modified="2010-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38758" source="BID">38758</ref>
      <ref url="http://www.exploit-db.com/exploits/11769" source="EXPLOIT-DB">11769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="3.1" />
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1227" published="2010-04-01" name="CVE-2010-1227" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF) attack involving the cmd and argv parameters to cmd.msc.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0157" source="VUPEN">ADV-2011-0157</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510154/100/0/threaded" source="BUGTRAQ">20100313 Sun Java System Communication Express CSRF via HPP</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html</ref>
      <ref url="http://secunia.com/advisories/42990" source="SECUNIA">42990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_communications_express">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1228" published="2010-04-01" name="CVE-2010-1228" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13829" source="OVAL">oval:org.mitre.oval:def:13829</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31880" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31880</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=28804" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=28804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1229" published="2010-04-01" name="CVE-2010-1229" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14220" source="OVAL">oval:org.mitre.oval:def:14220</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=31880" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=31880</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=28804" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=28804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1045" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1230" published="2010-04-01" name="CVE-2010-1230" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14292" source="OVAL">oval:org.mitre.oval:def:14292</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=33445" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=33445</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=30801" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=30801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers prev="1" num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1231" published="2010-04-01" name="CVE-2010-1231" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1036 processes HTTP headers before invoking the SafeBrowsing feature, which allows remote attackers to have an unspecified impact via crafted headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14332" source="OVAL">oval:org.mitre.oval:def:14332</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=33572" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1232" published="2010-04-01" name="CVE-2010-1232" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via a malformed SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14000" source="OVAL">oval:org.mitre.oval:def:14000</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=34978" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=34978</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1233" published="2010-04-01" name="CVE-2010-1233" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in Google Chrome before 4.1.249.1036 allow remote attackers to have an unspecified impact via vectors involving WebKit JavaScript objects.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14023" source="OVAL">oval:org.mitre.oval:def:14023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=35724" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=35724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1234" published="2010-04-01" name="CVE-2010-1234" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to truncate the URL shown in the HTTP Basic Authentication dialog via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14275" source="OVAL">oval:org.mitre.oval:def:14275</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=36772" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=36772</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1235" published="2010-04-01" name="CVE-2010-1235" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to trigger the omission of a download warning dialog via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14297" source="OVAL">oval:org.mitre.oval:def:14297</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=37007" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=37007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="4.0.244.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.89" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
        <vers num="4.1.249.1042" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1236" published="2010-04-01" name="CVE-2010-1236" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=35948" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=35948</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=41244" source="CONFIRM">http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=41244</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14067" source="OVAL">oval:org.mitre.oval:def:14067</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://flock.com/security/" source="CONFIRM">http://flock.com/security/</ref>
      <ref url="http://codereview.chromium.org/858001" source="CONFIRM">http://codereview.chromium.org/858001</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=37383" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=37383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flock" name="flock">
        <vers num="3.0.0.4094" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers prev="1" num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1237" published="2010-04-01" name="CVE-2010-1237" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via an empty SVG element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14374" source="OVAL">oval:org.mitre.oval:def:14374</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=37061" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=37061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1238" published="2010-04-05" name="CVE-2010-1238" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have empty values.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0831" source="VUPEN">ADV-2010-0831</ref>
      <ref url="http://www.ubuntu.com/usn/USN-925-1" source="UBUNTU">USN-925-1</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2024" source="DEBIAN">DSA-2024</ref>
      <ref url="http://secunia.com/advisories/39284" source="SECUNIA">39284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1239" published="2010-04-05" name="CVE-2010-1239" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/570177" source="CERT-VN" patch="1">VU#570177</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#0401" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#0401</ref>
      <ref url="http://www.foxitsoftware.com/announcements/2010420408.html" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/announcements/2010420408.html</ref>
      <ref url="http://www.f-secure.com/weblog/archives/00001923.html" source="MISC">http://www.f-secure.com/weblog/archives/00001923.html</ref>
      <ref url="http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/" source="MISC">http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/</ref>
      <ref url="http://blog.didierstevens.com/2010/03/29/escape-from-pdf/" source="MISC">http://blog.didierstevens.com/2010/03/29/escape-from-pdf/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_reader">
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.1.0.0824" />
        <vers num="3.1.1.0901" />
        <vers num="3.1.1.0928" />
        <vers num="3.1.3.1030" />
        <vers prev="1" num="3.2.0.0303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1240" published="2010-04-05" name="CVE-2010-1240" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-231A.html" source="CERT">TA10-231A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb10-15.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7466" source="OVAL">oval:org.mitre.oval:def:7466</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-April/006075.html" source="MLIST">[dailydave] 20100401 0day, it may not be</ref>
      <ref url="http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/" source="MISC">http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/</ref>
      <ref url="http://blog.didierstevens.com/2010/03/29/escape-from-pdf/" source="MISC">http://blog.didierstevens.com/2010/03/29/escape-from-pdf/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1241" published="2010-04-05" name="CVE-2010-1241" modified="2010-11-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103C.html" source="CERT">TA10-103C</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57589" source="XF">reader-customheap-code-execution(57589)</ref>
      <ref url="http://www.youtube.com/watch?v=9EVHtY1-0q8" source="MISC">http://www.youtube.com/watch?v=9EVHtY1-0q8</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0873" source="VUPEN" adv="1">ADV-2010-0873</ref>
      <ref url="http://www.securityfocus.com/bid/39329" source="BID">39329</ref>
      <ref url="http://www.securityfocus.com/bid/39227" source="BID">39227</ref>
      <ref url="http://www.blackhat.com/html/bh-eu-10/bh-eu-10-briefings.html#Li" source="MISC">http://www.blackhat.com/html/bh-eu-10/bh-eu-10-briefings.html#Li</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-09.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb10-09.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6940" source="OVAL">oval:org.mitre.oval:def:6940</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-April/006077.html" source="MLIST">[dailydave] 20100401 0day, it may not be</ref>
      <ref url="http://blog.fortinet.com/the-upcoming-blackhat-europe-2010-presentation/" source="MISC">http://blog.fortinet.com/the-upcoming-blackhat-europe-2010-presentation/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1242" published="2010-04-05" name="CVE-2010-1242" modified="2011-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24025662" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24025662</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0834" source="VUPEN">ADV-2011-0834</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0733" source="VUPEN" adv="1">ADV-2010-0733</ref>
      <ref url="http://secunia.com/advisories/39186" source="SECUNIA" adv="1">39186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="webi">
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1243" published="2010-04-05" name="CVE-2010-1243" modified="2011-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24025662" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24025662</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0834" source="VUPEN">ADV-2011-0834</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0733" source="VUPEN" adv="1">ADV-2010-0733</ref>
      <ref url="http://secunia.com/advisories/39186" source="SECUNIA" adv="1">39186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="webi">
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1244" published="2010-04-05" name="CVE-2010-1244" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://activemq.apache.org/activemq-531-release.html" source="CONFIRM" patch="1">http://activemq.apache.org/activemq-531-release.html</ref>
      <ref url="https://issues.apache.org/activemq/browse/AMQ-2625" source="CONFIRM">https://issues.apache.org/activemq/browse/AMQ-2625</ref>
      <ref url="https://issues.apache.org/activemq/browse/AMQ-2613" source="CONFIRM">https://issues.apache.org/activemq/browse/AMQ-2613</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57398" source="XF">activemq-web-console-csrf(57398)</ref>
      <ref url="http://secunia.com/advisories/39223" source="SECUNIA" adv="1">39223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="activemq">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="4.0" edition="m4" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="5.0.0" />
        <vers num="5.1.0" />
        <vers num="5.2.0" />
        <vers prev="1" num="5.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1245" published="2010-06-08" name="CVE-2010-1245" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511753/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel SxView Memory Corruption Vulnerability (CVE-2010-1245)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6877" source="OVAL">oval:org.mitre.oval:def:6877</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1246" published="2010-06-08" name="CVE-2010-1246" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511755/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel RTD Stack Overflow Vulnerability (CVE-2010-1246)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6839" source="OVAL">oval:org.mitre.oval:def:6839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1247" published="2010-06-08" name="CVE-2010-1247" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511754/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel RTD Heap Corruption Vulnerability (CVE-2010-1247)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6630" source="OVAL">oval:org.mitre.oval:def:6630</ref>
      <ref url="http://osvdb.org/65237" source="OSVDB">65237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1248" published="2010-06-08" name="CVE-2010-1248" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40526" source="BID">40526</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511765/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel HFPicture Buffer Overflow Vulnerability (CVE-2010-1248)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7223" source="OVAL">oval:org.mitre.oval:def:7223</ref>
      <ref url="http://osvdb.org/65235" source="OSVDB">65235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1249" published="2010-06-08" name="CVE-2010-1249" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40527" source="BID">40527</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511767/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel ExternName Buffer Overflow Vulnerability (CVE-2010-1249)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6634" source="OVAL">oval:org.mitre.oval:def:6634</ref>
      <ref url="http://osvdb.org/65232" source="OSVDB">65232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1250" published="2010-06-08" name="CVE-2010-1250" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40528" source="BID">40528</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511756/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Microsoft Office Excel EDG Heap Overflow Vulnerability (CVE-2010-1250)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7593" source="OVAL">oval:org.mitre.oval:def:7593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1251" published="2010-06-08" name="CVE-2010-1251" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40529" source="BID">40529</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6761" source="OVAL">oval:org.mitre.oval:def:6761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1252" published="2010-06-08" name="CVE-2010-1252" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40530" source="BID">40530</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7369" source="OVAL">oval:org.mitre.oval:def:7369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1253" published="2010-06-08" name="CVE-2010-1253" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to execute arbitrary code via an Excel file with crafted DBQueryExt records that allow a function call to a "user-controlled pointer," aka "Excel ADO Object Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-103" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511728/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-103: Microsoft Office Excel DBQueryExt Record Unspecified ADO Object Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6842" source="OVAL">oval:org.mitre.oval:def:6842</ref>
      <ref url="http://osvdb.org/65228" source="OSVDB">65228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1254" published="2010-06-08" name="CVE-2010-1254" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx" source="MS" patch="1" adv="1">MS10-038</ref>
      <ref url="http://www.securityfocus.com/bid/40533" source="BID">40533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1255" published="2010-06-08" name="CVE-2010-1255" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-032.mspx" source="MS" patch="1" adv="1">MS10-032</ref>
      <ref url="http://www.opera.com/support/kb/view/954/" source="CONFIRM">http://www.opera.com/support/kb/view/954/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7283" source="OVAL">oval:org.mitre.oval:def:7283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1256" published="2010-06-08" name="CVE-2010-1256" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/bulletin/ms10-040.mspx

'Mitigating Factors for IIS Authentication Memory Corruption Vulnerability - CVE-2010-1256

Without the installation of KB973917 on Windows Server 2003, Windows Vista, and Windows Server 2008, systems will not have the Extended Protection for Authentication feature and will not be vulnerable.

Extended Protection for Authentication is not enabled by default on any affected platform, even when a system has installed KB973917. Systems are only affected when this feature is enabled.'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-040.mspx" source="MS" patch="1" adv="1">MS10-040</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58864" source="XF">ms-iis-authentication-code-execution(58864)</ref>
      <ref url="http://www.securityfocus.com/bid/40573" source="BID">40573</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7149" source="OVAL">oval:org.mitre.oval:def:7149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1257" published="2010-06-08" name="CVE-2010-1257" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2; Office SharePoint Server 2007 SP1 and SP2; SharePoint Services 3.0 SP1 and SP2; and Internet Explorer 8 allows remote attackers to inject arbitrary web script or HTML via vectors related to sanitization.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx" source="MS" patch="1" adv="1">MS10-039</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS" patch="1" adv="1">MS10-035</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58866" source="XF">ie-tostatichtml-information-disclosure(58866)</ref>
      <ref url="http://www.securityfocus.com/bid/40409" source="BID">40409</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6677" source="OVAL">oval:org.mitre.oval:def:6677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
      <prod vendor="microsoft" name="office_infopath">
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x32" />
        <vers num="2007" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="sharepoint_services">
        <vers num="3.0" edition="sp1" />
        <vers num="3.0" edition="sp1:x32" />
        <vers num="3.0" edition="sp1:x64" />
        <vers num="3.0" edition="sp2" />
        <vers num="3.0" edition="sp2:x32" />
        <vers num="3.0" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1258" published="2010-08-11" name="CVE-2010-1258" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-053.mspx" source="MS" patch="1" adv="1">MS10-053</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11954" source="OVAL">oval:org.mitre.oval:def:11954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1259" published="2010-06-08" name="CVE-2010-1259" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS" patch="1" adv="1">MS10-035</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7324" source="OVAL">oval:org.mitre.oval:def:7324</ref>
      <ref url="http://osvdb.org/65215" source="OSVDB">65215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1260" published="2010-06-08" name="CVE-2010-1260" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS" patch="1" adv="1">MS10-035</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6686" source="OVAL">oval:org.mitre.oval:def:6686</ref>
      <ref url="http://osvdb.org/65213" source="OSVDB">65213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1261" published="2010-06-08" name="CVE-2010-1261" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS" patch="1" adv="1">MS10-035</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7124" source="OVAL">oval:org.mitre.oval:def:7124</ref>
      <ref url="http://osvdb.org/65214" source="OSVDB">65214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1262" published="2010-06-08" name="CVE-2010-1262" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-035.mspx" source="MS" patch="1" adv="1">MS10-035</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-102/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-102/</ref>
      <ref url="http://www.securityfocus.com/bid/40417" source="BID">40417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511727/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-102: Microsoft Internet Explorer Stylesheet Array Removal Remote Code Execution Vulnerability</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100089747" source="CONFIRM">http://support.avaya.com/css/P8/documents/100089747</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7406" source="OVAL">oval:org.mitre.oval:def:7406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1263" published="2010-06-08" name="CVE-2010-1263" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not properly validate COM objects during instantiation, which allows remote attackers to execute arbitrary code via a crafted file, aka "COM Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-285A.html" source="CERT">TA10-285A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-036.mspx" source="MS" patch="1" adv="1">MS10-036</ref>
      <ref url="http://www.securitytracker.com/id?1024555" source="SECTRACK">1024555</ref>
      <ref url="http://www.securityfocus.com/bid/40574" source="BID">40574</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-083.mspx" source="MS">MS10-083</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7286" source="OVAL">oval:org.mitre.oval:def:7286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1264" published="2010-06-08" name="CVE-2010-1264" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Windows SharePoint Services 3.0 SP1 and SP2 allows remote attackers to cause a denial of service (hang) via crafted requests to the Help page that cause repeated restarts of the application pool, aka "Sharepoint Help Page Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-039.mspx" source="MS" patch="1" adv="1">MS10-039</ref>
      <ref url="http://www.securityfocus.com/bid/40559" source="BID">40559</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7241" source="OVAL">oval:org.mitre.oval:def:7241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="sharepoint_services">
        <vers num="3.0" edition="sp1" />
        <vers num="3.0" edition="sp1:x32" />
        <vers num="3.0" edition="sp1:x64" />
        <vers num="3.0" edition="sp2" />
        <vers num="3.0" edition="sp2:x32" />
        <vers num="3.0" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1265" published="2010-04-06" name="CVE-2010-1265" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38981" source="BID">38981</ref>
      <ref url="http://www.exploit-db.com/exploits/11884" source="EXPLOIT-DB">11884</ref>
      <ref url="http://secunia.com/advisories/39161" source="SECUNIA" adv="1">39161</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomladcsflashgames-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomladcsflashgames-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ekith" name="com_dcs_flashgames">
        <vers num="2.0" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1266" published="2010-04-06" name="CVE-2010-1266" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) template, (2) menu, (3) events, and (4) SITEROOT parameters to template/babyweb/index.php; the (5) modules and (6) copyright parameters to template/calm/footer.php; the (7) menu parameter to template/calm/top.php; and the (8) modules, (9) copyright, and (10) menu parameters to template/wm025/footer.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57059" source="XF">webmaidcms-index-file-include(57059)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0674" source="VUPEN" adv="1">ADV-2010-0674</ref>
      <ref url="http://www.securityfocus.com/bid/38993" source="BID">38993</ref>
      <ref url="http://www.exploit-db.com/exploits/11831" source="EXPLOIT-DB">11831</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txt</ref>
      <ref url="http://inj3ct0r.com/exploits/11394" source="MISC">http://inj3ct0r.com/exploits/11394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kjetiltroan" name="webmaid_cms">
        <vers prev="1" num="0.2-6" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1267" published="2010-04-06" name="CVE-2010-1267" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the com parameter to (1) cContactus.php, (2) cGuestbook.php, and (3) cArticle.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0674" source="VUPEN" adv="1">ADV-2010-0674</ref>
      <ref url="http://www.securityfocus.com/bid/38993" source="BID">38993</ref>
      <ref url="http://www.exploit-db.com/exploits/11831" source="EXPLOIT-DB">11831</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/webmaid-rfilfi.txt</ref>
      <ref url="http://inj3ct0r.com/exploits/11394" source="MISC">http://inj3ct0r.com/exploits/11394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kjetiltroan" name="webmaid_cms">
        <vers prev="1" num="0.2-6" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1268" published="2010-04-06" name="CVE-2010-1268" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files directory traversal sequences in the p parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57174" source="XF">justvisualcms-index-file-include(57174)</ref>
      <ref url="http://www.securityfocus.com/bid/38970" source="BID">38970</ref>
      <ref url="http://www.exploit-db.com/exploits/11876" source="EXPLOIT-DB">11876</ref>
      <ref url="http://secunia.com/advisories/39093" source="SECUNIA" adv="1">39093</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/justvisual-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/justvisual-lfi.txt</ref>
      <ref url="http://osvdb.org/63156" source="OSVDB">63156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fh54" name="justvisual">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1269" published="2010-04-06" name="CVE-2010-1269" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57020" source="XF">niedrig-auktion-sql-injection(57020)</ref>
      <ref url="http://www.exploit-db.com/exploits/11805" source="EXPLOIT-DB">11805</ref>
      <ref url="http://secunia.com/advisories/38971" source="SECUNIA" adv="1">38971</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/phpscripte24-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/phpscripte24-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/18/phpscripte24-niedrig-gebote-pro-auktions-system-ii-blind-sql-injection-auktion-php/" source="MISC">http://4004securityproject.wordpress.com/2010/03/18/phpscripte24-niedrig-gebote-pro-auktions-system-ii-blind-sql-injection-auktion-php/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="niedrig_gebote_pro_auktions_system_ii">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1270" published="2010-04-06" name="CVE-2010-1270" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56935" source="XF">auktionhaus-auktion-sql-injection(56935)</ref>
      <ref url="http://www.securityfocus.com/bid/38793" source="BID">38793</ref>
      <ref url="http://www.osvdb.org/63048" source="OSVDB">63048</ref>
      <ref url="http://www.exploit-db.com/exploits/11776" source="EXPLOIT-DB">11776</ref>
      <ref url="http://secunia.com/advisories/38971" source="SECUNIA" adv="1">38971</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/multiauktions-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/multiauktions-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/16/phpscripte24-auktionshaus-community-standart-system/" source="MISC">http://4004securityproject.wordpress.com/2010/03/16/phpscripte24-auktionshaus-community-standart-system/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="multi_suktions_komplett_system">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1271" published="2010-04-06" name="CVE-2010-1271" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands via the domain parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56676" source="XF">smartplugs-showplugs-sql-injection(56676)</ref>
      <ref url="http://www.securityfocus.com/bid/38529" source="BID">38529</ref>
      <ref url="http://www.exploit-db.com/exploits/11623" source="EXPLOIT-DB">11623</ref>
      <ref url="http://secunia.com/advisories/38819" source="SECUNIA" adv="1">38819</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/smartplugs-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/smartplugs-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/03/smartplugs-1-3-sql-injection-showplugs-php" source="MISC">http://4004securityproject.wordpress.com/2010/03/03/smartplugs-1-3-sql-injection-showplugs-php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smart-plugs" name="smartplugs">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1272" published="2010-04-06" name="CVE-2010-1272" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56675" source="XF">gnattgp-tgpinc-file-include(56675)</ref>
      <ref url="http://www.securityfocus.com/bid/38522" source="BID">38522</ref>
      <ref url="http://www.exploit-db.com/exploits/11621" source="EXPLOIT-DB">11621</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/gnattgp-rfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/gnattgp-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="komputer.boo" name="gnat-tgp">
        <vers prev="1" num="1.2.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1273" published="2010-04-06" name="CVE-2010-1273" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.html" source="CONFIRM" patch="1">http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.html</ref>
      <ref url="http://www.securityfocus.com/bid/38541" source="BID">38541</ref>
      <ref url="http://www.osvdb.org/62717" source="OSVDB">62717</ref>
      <ref url="http://secunia.com/advisories/38759" source="SECUNIA" adv="1">38759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emweb" name="wt">
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.4" />
        <vers num="2.0.4a" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.99.0" />
        <vers num="2.99.1" />
        <vers num="2.99.2" />
        <vers num="2.99.3" />
        <vers num="2.99.4" />
        <vers num="2.99.5" />
        <vers num="3.0.0" />
        <vers prev="1" num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1274" published="2010-04-06" name="CVE-2010-1274" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Emweb Wt before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to "insertions of the URL" that occur during a redirection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56681" source="XF">wt-unspecified-xss(56681)</ref>
      <ref url="http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.html" source="CONFIRM" adv="1">http://www.webtoolkit.eu/wt/doc/reference/html/Releasenotes.html</ref>
      <ref url="http://www.securityfocus.com/bid/38541" source="BID">38541</ref>
      <ref url="http://www.osvdb.org/62716" source="OSVDB">62716</ref>
      <ref url="http://secunia.com/advisories/38759" source="SECUNIA" adv="1">38759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webtoolkit" name="wt">
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.99.0" />
        <vers num="2.99.1" />
        <vers num="2.99.2" />
        <vers num="2.99.3" />
        <vers num="2.99.4" />
        <vers num="2.99.5" />
        <vers num="3.0.0" />
        <vers prev="1" num="3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1275" published="2010-04-06" name="CVE-2010-1275" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ShowPost.asp in BBSXP 2008 allows remote attackers to inject arbitrary web script or HTML via the ThreadID parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38542" source="BID">38542</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509860/100/0/threaded" source="BUGTRAQ">20100304 [xss] a xss on "ThreadID" parameter in BBSXP 2008 from china</ref>
      <ref url="http://secunia.com/advisories/38855" source="SECUNIA" adv="1">38855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbsxp" name="bbsxp">
        <vers num="2008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1276" published="2010-04-06" name="CVE-2010-1276" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in BBSXP 2008 SP2 allow remote attackers to inject arbitrary web script or HTML via the URI in a request to (1) AddPost.asp, (2) AddTopic.asp, (3) Admin_Default.asp, (4) Bank.asp, (5) Manage.asp, and (6) ShowPost.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38855" source="SECUNIA" adv="1">38855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbsxp" name="bbsxp">
        <vers num="2008" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1277" published="2010-04-06" name="CVE-2010-1277" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the user.authenticate method in the API in Zabbix 1.8 before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the user parameter in JSON data to api_jsonrpc.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zabbix.com/rn1.8.2.php" source="MISC" patch="1">http://www.zabbix.com/rn1.8.2.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0799" source="VUPEN" adv="1">ADV-2010-0799</ref>
      <ref url="http://www.securityfocus.com/bid/39148" source="BID">39148</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510480/100/0/threaded" source="BUGTRAQ">20100401 Zabbix &lt;= 1.8.1 SQL Injection</ref>
      <ref url="http://www.osvdb.org/63456" source="OSVDB">63456</ref>
      <ref url="http://secunia.com/advisories/39119" source="SECUNIA" adv="1">39119</ref>
      <ref url="http://legalhackers.com/poc/zabbix181api.pl-poc" source="MISC">http://legalhackers.com/poc/zabbix181api.pl-poc</ref>
      <ref url="http://legalhackers.com/advisories/zabbix181api-sql.txt" source="MISC">http://legalhackers.com/advisories/zabbix181api-sql.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0001.html" source="FULLDISC">20100401 Zabbix &lt;= 1.8.1 SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zabbix" name="zabbix">
        <vers num="1.8" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1278" published="2010-04-22" name="CVE-2010-1278" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x before 9.3, allows remote attackers to execute arbitrary code via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-02.html" source="CONFIRM" patch="1">http://www.adobe.com/support/security/bulletins/apsb10-02.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-077/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-077/</ref>
      <ref url="http://www.securitytracker.com/id?1023908" source="SECTRACK">1023908</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510868/100/0/threaded" source="BUGTRAQ">20100421 ZDI-10-077: Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7500" source="OVAL">oval:org.mitre.oval:def:7500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="8.0.0" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1279" published="2010-05-05" name="CVE-2010-1279" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1 allow user-assisted remote attackers to execute arbitrary code via a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1049" source="VUPEN" patch="1" adv="1">ADV-2010-1049</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-10.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-10.html</ref>
      <ref url="http://www.securityfocus.com/bid/39849" source="BID">39849</ref>
      <ref url="http://secunia.com/advisories/39711" source="SECUNIA" adv="1">39711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="photoshop_cs4">
        <vers num="11.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1280" published="2010-05-13" name="CVE-2010-1280" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4937.php" source="MISC">http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4937.php</ref>
      <ref url="http://www.zeroscience.mk/codes/shockwave_mem.txt" source="MISC">http://www.zeroscience.mk/codes/shockwave_mem.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511257/100/0/threaded" source="BUGTRAQ">20100512 [CAL-20100204-3]Adobe Shockwave Player Director File Parsing RCSL Pointer Overwrite</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7184" source="OVAL">oval:org.mitre.oval:def:7184</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0139.html" source="FULLDISC">20100511 [CAL-20100204-3]Adobe Shockwave Player Director File Parsing RCSL Pointer Overwrite</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1281" published="2010-05-13" name="CVE-2010-1281" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-087/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-087/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511252/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-087: Adobe Shockwave Invalid Offset Memory Corruption Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7268" source="OVAL">oval:org.mitre.oval:def:7268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1282" published="2010-05-13" name="CVE-2010-1282" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40088" source="BID">40088</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511254/100/0/threaded" source="BUGTRAQ">20100512 [CAL-20100204-1]Adobe Shockwave Player Director File Parsing ATOM size infinite loop vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7388" source="OVAL">oval:org.mitre.oval:def:7388</ref>
      <ref url="http://hi.baidu.com/fs_fx/blog/item/f8de1d18ba8c9b76dbb4bd56.html" source="MISC">http://hi.baidu.com/fs_fx/blog/item/f8de1d18ba8c9b76dbb4bd56.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0137.html" source="FULLDISC">20100511 [CAL-20100204-1]Adobe Shockwave Player Director File Parsing ATOM size infinite loop vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1283" published="2010-05-13" name="CVE-2010-1283" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-088/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-088/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511253/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-088: Adobe Shockwave Player 3D Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7262" source="OVAL">oval:org.mitre.oval:def:7262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1284" published="2010-05-13" name="CVE-2010-1284" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40091" source="BID">40091</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6638" source="OVAL">oval:org.mitre.oval:def:6638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1285" published="2010-06-30" name="CVE-2010-1285" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified manipulations involving the newclass (0x58) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-2168 and CVE-2010-2201.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-15.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-15.html</ref>
      <ref url="http://www.securityfocus.com/bid/41232" source="BID">41232</ref>
      <ref url="http://www.securityfocus.com/archive/1/512099" source="BUGTRAQ">20100630 VUPEN Security Research - Adobe Acrobat and Reader "newclass" Memory Corruption Vulnerability (CVE-2010-1285)</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6725" source="OVAL">oval:org.mitre.oval:def:6725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1286" published="2010-05-13" name="CVE-2010-1286" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7269" source="OVAL">oval:org.mitre.oval:def:7269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1287" published="2010-05-13" name="CVE-2010-1287" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6803" source="OVAL">oval:org.mitre.oval:def:6803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1288" published="2010-05-13" name="CVE-2010-1288" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7543" source="OVAL">oval:org.mitre.oval:def:7543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1289" published="2010-05-13" name="CVE-2010-1289" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.securityfocus.com/bid/40087" source="BID">40087</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6652" source="OVAL">oval:org.mitre.oval:def:6652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1290" published="2010-05-13" name="CVE-2010-1290" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1291.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7154" source="OVAL">oval:org.mitre.oval:def:7154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1291" published="2010-05-13" name="CVE-2010-1291" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7183" source="OVAL">oval:org.mitre.oval:def:7183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1292" published="2010-05-13" name="CVE-2010-1292" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-12.html

'Adobe recommends users of Adobe Shockwave Player 11.5.6.606 and earlier versions update to Adobe Shockwave Player 11.5.7.609'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1128" source="VUPEN" patch="1" adv="1">ADV-2010-1128</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-12.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-12.html</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-089/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-089/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511242/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-089: Adobe Shockwave Director PAMI Chunk Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38751" source="SECUNIA" adv="1">38751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7416" source="OVAL">oval:org.mitre.oval:def:7416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0" />
        <vers num="10.1.0.11" />
        <vers num="11.0.0.456" />
        <vers num="11.5.0.595" />
        <vers num="11.5.0.596" />
        <vers num="11.5.1.601" />
        <vers num="11.5.2.602" />
        <vers prev="1" num="11.5.6.606" />
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="8.0" />
        <vers num="8.5.1" />
        <vers num="9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1293" published="2010-05-13" name="CVE-2010-1293" modified="2010-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-11.html

'Affected software versions

ColdFusion 8.0, 8.0.1, 9.0 and earlier versions for Windows, Macintosh and UNIX'</impact>
    </impacts>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1127" source="VUPEN" patch="1" adv="1">ADV-2010-1127</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-11.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-11.html</ref>
      <ref url="http://secunia.com/advisories/39790" source="SECUNIA" adv="1">39790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.2" edition="unknown" />
        <vers num="7.2" edition="unknown:mx" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1294" published="2010-05-13" name="CVE-2010-1294" modified="2010-05-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-11.html

'Affected software versions

ColdFusion 8.0, 8.0.1, 9.0 and earlier versions for Windows, Macintosh and UNIX'</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1127" source="VUPEN" patch="1" adv="1">ADV-2010-1127</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-11.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-11.html</ref>
      <ref url="http://secunia.com/advisories/39790" source="SECUNIA" adv="1">39790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="coldfusion">
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.2" edition="unknown" />
        <vers num="7.2" edition="unknown:mx" />
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1295" published="2010-06-30" name="CVE-2010-1295" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb10-15.html
 
'This update resolves a memory corruption vulnerability that could lead to code execution (CVE-2010-1295).'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-15.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-15.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7504" source="OVAL">oval:org.mitre.oval:def:7504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1296" published="2010-05-27" name="CVE-2010-1296" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-13.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb10-13.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58888" source="XF">photoshopcs4-multiple-code-execution(58888)</ref>
      <ref url="http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4940.php" source="MISC">http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4940.php</ref>
      <ref url="http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4939.php" source="MISC">http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4939.php</ref>
      <ref url="http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4938.php" source="MISC">http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4938.php</ref>
      <ref url="http://www.zeroscience.mk/codes/psstyle_bof.txt" source="MISC">http://www.zeroscience.mk/codes/psstyle_bof.txt</ref>
      <ref url="http://www.zeroscience.mk/codes/psgradient_bof.txt" source="MISC">http://www.zeroscience.mk/codes/psgradient_bof.txt</ref>
      <ref url="http://www.zeroscience.mk/codes/psbrush_bof.txt" source="MISC">http://www.zeroscience.mk/codes/psbrush_bof.txt</ref>
      <ref url="http://www.securitytracker.com/id?1024042" source="SECTRACK">1024042</ref>
      <ref url="http://www.securityfocus.com/bid/40389" source="BID">40389</ref>
      <ref url="http://www.exploit-db.com/exploits/12753" source="EXPLOIT-DB">12753</ref>
      <ref url="http://www.exploit-db.com/exploits/12752" source="EXPLOIT-DB">12752</ref>
      <ref url="http://www.exploit-db.com/exploits/12751" source="EXPLOIT-DB">12751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="photoshop_cs4">
        <vers num="11.0" />
        <vers prev="1" num="11.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1297" published="2010-06-08" name="CVE-2010-1297" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-162A.html" source="CERT">TA10-162A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159A.html" source="CERT">TA10-159A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/486225" source="CERT-VN">VU#486225</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59137" source="XF">adobe-authplay-code-execution(59137)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0192" source="VUPEN">ADV-2011-0192</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1793" source="VUPEN">ADV-2010-1793</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1522" source="VUPEN">ADV-2010-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1482" source="VUPEN">ADV-2010-1482</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1453" source="VUPEN">ADV-2010-1453</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1434" source="VUPEN">ADV-2010-1434</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1432" source="VUPEN">ADV-2010-1432</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1421" source="VUPEN">ADV-2010-1421</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1349" source="VUPEN" adv="1">ADV-2010-1349</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1348" source="VUPEN" adv="1">ADV-2010-1348</ref>
      <ref url="http://www.turbolinux.co.jp/security/2010/TLSA-2010-19j.txt" source="TURBO">TLSA-2010-19</ref>
      <ref url="http://www.securityfocus.com/bid/40759" source="BID">40759</ref>
      <ref url="http://www.securityfocus.com/bid/40586" source="BID">40586</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0470.html" source="REDHAT">RHSA-2010:0470</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0464.html" source="REDHAT">RHSA-2010:0464</ref>
      <ref url="http://www.osvdb.org/65141" source="OSVDB">65141</ref>
      <ref url="http://www.exploit-db.com/exploits/13787" source="EXPLOIT-DB">13787</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-15.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb10-15.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb10-14.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb10-14.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa10-01.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/advisories/apsa10-01.html</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securitytracker.com/id?1024086" source="SECTRACK">1024086</ref>
      <ref url="http://securitytracker.com/id?1024085" source="SECTRACK">1024085</ref>
      <ref url="http://securitytracker.com/id?1024058" source="SECTRACK">1024058</ref>
      <ref url="http://securitytracker.com/id?1024057" source="SECTRACK">1024057</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-09.xml" source="GENTOO">GLSA-201101-09</ref>
      <ref url="http://secunia.com/advisories/43026" source="SECUNIA">43026</ref>
      <ref url="http://secunia.com/advisories/40545" source="SECUNIA">40545</ref>
      <ref url="http://secunia.com/advisories/40144" source="SECUNIA">40144</ref>
      <ref url="http://secunia.com/advisories/40034" source="SECUNIA" adv="1">40034</ref>
      <ref url="http://secunia.com/advisories/40026" source="SECUNIA" adv="1">40026</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7116" source="OVAL">oval:org.mitre.oval:def:7116</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00000.html" source="SUSE">SUSE-SA:2010:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751" source="HP">SSRT100179</ref>
      <ref url="http://community.websense.com/blogs/securitylabs/archive/2010/06/09/having-fun-with-adobe-0-day-exploits.aspx" source="MISC">http://community.websense.com/blogs/securitylabs/archive/2010/06/09/having-fun-with-adobe-0-day-exploits.aspx</ref>
      <ref url="http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited-0-day-for-adobe-reader-and-adobe-flash/" source="MISC">http://blog.zynamics.com/2010/06/09/analyzing-the-currently-exploited-0-day-for-adobe-reader-and-adobe-flash/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers prev="1" num="9.3.2" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.3" />
        <vers num="9.3.1" />
        <vers prev="1" num="9.3.2" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers num="10.0.12.36" />
        <vers num="10.0.15.3" />
        <vers num="10.0.22.87" />
        <vers num="10.0.32.18" />
        <vers num="10.0.42.34" />
        <vers prev="1" num="10.0.45.2" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.125.0" />
        <vers num="9.0.151.0" />
        <vers num="9.0.152.0" />
        <vers num="9.0.159.0" />
        <vers num="9.0.16" />
        <vers num="9.0.18d60" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.246.0" />
        <vers num="9.0.260.0" />
        <vers prev="1" num="9.0.262.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1298" published="2010-04-06" name="CVE-2010-1298" modified="2010-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in view.php in Pulse CMS 1.2.2 allows remote attackers to read arbitrary files via directory traversal sequences in the f parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
      <descript source="nvd">per: http://secunia.com/advisories/38650

'2) Input passed via the "f" parameter to view.php is not properly sanitised before being used to read files. This can be exploited to disclose the content of local files via directory traversal sequences.

Successful exploitation of this vulnerability requires authentication.'</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38650" source="SECUNIA" adv="1">38650</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1299" published="2010-04-07" name="CVE-2010-1299" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.php, (2) PathToRoot parameter to plugins/DPGguestbook/guestbookaction.php and (3) get_popUpResource parameter to backendpopup/popup.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57491" source="XF">dynphcms-popup-file-include(57491)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57490" source="XF">dynphcms-guestbookaction-file-include(57490)</ref>
      <ref url="http://www.securityfocus.com/bid/39168" source="BID">39168</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510477/100/0/threaded" source="BUGTRAQ">20100401 DynPG CMS v4.1.0 Multiple Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/11994" source="EXPLOIT-DB">11994</ref>
      <ref url="http://www.dynpg.org/cms-freeware.php?t=DynPG-Update+4.1.1+noch+einfacher+und+sicherer%21&amp;read_article=169" source="CONFIRM">http://www.dynpg.org/cms-freeware.php?t=DynPG-Update+4.1.1+noch+einfacher+und+sicherer!&amp;read_article=169</ref>
      <ref url="http://secunia.com/advisories/39185" source="SECUNIA" adv="1">39185</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/dynpgcms-rfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/dynpgcms-rfi.txt</ref>
      <ref url="http://osvdb.org/63415" source="OSVDB">63415</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dynpg" name="dynpg_cms">
        <vers num="3.4.0" />
        <vers num="3.4.4" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="4.0.0" />
        <vers prev="1" num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1300" published="2010-04-07" name="CVE-2010-1300" modified="2010-06-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59404" source="XF">yamamah-calbums-sql-injection(59404)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57415" source="XF">yamamah-index-sql-injection(57415)</ref>
      <ref url="http://www.securityfocus.com/bid/39690" source="BID">39690</ref>
      <ref url="http://www.exploit-db.com/exploits/13857" source="EXPLOIT-DB">13857</ref>
      <ref url="http://www.exploit-db.com/exploits/13849" source="EXPLOIT-DB">13849</ref>
      <ref url="http://www.exploit-db.com/exploits/11947" source="EXPLOIT-DB">11947</ref>
      <ref url="http://secunia.com/advisories/39205" source="SECUNIA" adv="1">39205</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/yamamah-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/yamamah-sql.txt</ref>
      <ref url="http://osvdb.org/63344" source="OSVDB">63344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yamamah" name="yamamah">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1301" published="2010-04-07" name="CVE-2010-1301" modified="2011-11-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57464" source="XF">centreon-hostid-sql-injection(57464)</ref>
      <ref url="http://www.securityfocus.com/bid/39118" source="BID">39118</ref>
      <ref url="http://www.exploit-db.com/exploits/11979" source="EXPLOIT-DB">11979</ref>
      <ref url="http://secunia.com/advisories/39236" source="SECUNIA" adv="1">39236</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/centreon-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/centreon-sql.txt</ref>
      <ref url="http://osvdb.org/63347" source="OSVDB">63347</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merethis" name="centreon">
        <vers num="2.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1302" published="2010-04-07" name="CVE-2010-1302" modified="2010-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39108" source="BID">39108</ref>
      <ref url="http://www.exploit-db.com/exploits/11978" source="EXPLOIT-DB">11978</ref>
      <ref url="http://secunia.com/advisories/39200" source="SECUNIA" adv="1">39200</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomladwgraph-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomladwgraph-lfi.txt</ref>
      <ref url="http://osvdb.org/63345" source="OSVDB">63345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="decryptweb" name="com_dwgraphs">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1303" published="2010-04-08" name="CVE-2010-1303" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Filter module 6.x before 6.x-1.1 for Drupal allow remote authenticated users, with administer taxonomy permissions or create node permissions when free tagging is enabled, to inject arbitrary web script or HTML via vocabulary (1) names, (2) terms, and (3) filter menus.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/758756" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/758756</ref>
      <ref url="http://drupal.org/node/622096" source="CONFIRM" patch="1">http://drupal.org/node/622096</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57445" source="XF">taxonomy-names-xss(57445)</ref>
      <ref url="http://www.osvdb.org/63425" source="OSVDB">63425</ref>
      <ref url="http://secunia.com/advisories/39220" source="SECUNIA" adv="1">39220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jim_berry" name="taxonomy_filter">
        <vers num="6.x-1.0" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1304" published="2010-04-08" name="CVE-2010-1304" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57483" source="XF">userstatus-controller-file-include(57483)</ref>
      <ref url="http://www.securityfocus.com/bid/39174" source="BID">39174</ref>
      <ref url="http://www.exploit-db.com/exploits/11998" source="EXPLOIT-DB">11998</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlamo" name="com_userstatus">
        <vers num="1.21.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1305" published="2010-04-08" name="CVE-2010-1305" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in jinventory.php in the JInventory (com_jinventory) component 1.23.02 and possibly other versions before 1.26.03, a module for Joomla!, allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://extensions.joomla.org/extensions/e-commerce/shopping-cart/7951" source="MISC" patch="1">http://extensions.joomla.org/extensions/e-commerce/shopping-cart/7951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57538" source="XF">jinventory-controller-file-include(57538)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0811" source="VUPEN" adv="1">ADV-2010-0811</ref>
      <ref url="http://www.securityfocus.com/bid/39203" source="BID">39203</ref>
      <ref url="http://www.exploit-db.com/exploits/12065" source="EXPLOIT-DB">12065</ref>
      <ref url="http://secunia.com/advisories/39351" source="SECUNIA" adv="1">39351</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/jinventory-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/jinventory-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlamo" name="com_jinventory">
        <vers num="1.23.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1306" published="2010-04-08" name="CVE-2010-1306" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57508" source="XF">picasa-controller-file-include(57508)</ref>
      <ref url="http://www.securityfocus.com/bid/39200" source="BID">39200</ref>
      <ref url="http://www.exploit-db.com/exploits/12058" source="EXPLOIT-DB">12058</ref>
      <ref url="http://secunia.com/advisories/39338" source="SECUNIA" adv="1">39338</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlapicasa-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlapicasa-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roberto_aloi" name="com_joomlapicasa2">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1307" published="2010-04-08" name="CVE-2010-1307" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57531" source="XF">magicupdater-controller-file-include(57531)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0806" source="VUPEN" adv="1">ADV-2010-0806</ref>
      <ref url="http://www.securityfocus.com/bid/39207" source="BID">39207</ref>
      <ref url="http://www.exploit-db.com/exploits/12070" source="EXPLOIT-DB">12070</ref>
      <ref url="http://secunia.com/advisories/39348" source="SECUNIA" adv="1">39348</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaupdater-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaupdater-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="software.realtyna" name="com_joomlaupdater">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="3.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1308" published="2010-04-08" name="CVE-2010-1308" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0809" source="VUPEN" adv="1">ADV-2010-0809</ref>
      <ref url="http://www.exploit-db.com/exploits/12066" source="EXPLOIT-DB">12066</ref>
      <ref url="http://secunia.com/advisories/39350" source="SECUNIA" adv="1">39350</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlasvmap-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlasvmap-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="la-souris-verte" name="com_svmap">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1309" published="2010-04-08" name="CVE-2010-1309" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary files via a .. (dot dot) in the w parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11938" source="EXPLOIT-DB">11938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ermenegildo_fiorito" name="irmin_cms">
        <vers num="0.6" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1310" published="2010-04-08" name="CVE-2010-1310" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.opera.com/support/kb/view/949/" source="CONFIRM" adv="1">http://www.opera.com/support/kb/view/949/</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/1051/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/1051/</ref>
      <ref url="http://secunia.com/advisories/38820" source="SECUNIA" adv="1">38820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="10.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1311" published="2010-04-08" name="CVE-2010-1311" modified="2010-08-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39262" source="BID" patch="1">39262</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1771" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1771</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1206" source="VUPEN">ADV-2010-1206</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0909" source="VUPEN">ADV-2010-0909</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0832" source="VUPEN">ADV-2010-0832</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0827" source="VUPEN">ADV-2010-0827</ref>
      <ref url="http://www.ubuntu.com/usn/USN-926-1" source="UBUNTU">USN-926-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:082" source="MANDRIVA">MDVSA-2010:082</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://secunia.com/advisories/39329" source="SECUNIA" adv="1">39329</ref>
      <ref url="http://secunia.com/advisories/39293" source="SECUNIA">39293</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96" source="CONFIRM">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc" />
        <vers num="0.80" edition="rc2" />
        <vers num="0.80" edition="rc3" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" edition="rc1" />
        <vers num="0.84" edition="rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" edition="rc1" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.9" edition="rc1" />
        <vers num="0.90" edition="rc1" />
        <vers num="0.90" edition="rc1.1" />
        <vers num="0.90" edition="rc2" />
        <vers num="0.90" edition="rc3" />
        <vers num="0.90.1" />
        <vers num="0.90.2" />
        <vers num="0.90.3" />
        <vers num="0.91" edition="rc1" />
        <vers num="0.91" edition="rc2" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
        <vers num="0.95" edition="rc1" />
        <vers num="0.95" edition="rc2" />
        <vers num="0.95.1" />
        <vers num="0.95.2" />
        <vers num="0.95.3" />
        <vers prev="1" num="0.96" edition="rc1" />
        <vers prev="1" num="0.96" edition="rc2" />
      </prod>
      <prod vendor="clamavs" name="clamav">
        <vers num="0.04" />
        <vers num="0.06" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1312" published="2010-04-08" name="CVE-2010-1312" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39222" source="BID">39222</ref>
      <ref url="http://www.exploit-db.com/exploits/12077" source="EXPLOIT-DB">12077</ref>
      <ref url="http://secunia.com/advisories/39289" source="SECUNIA" adv="1">39289</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlanewportal-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlanewportal-lfi.txt</ref>
      <ref url="http://osvdb.org/63572" source="OSVDB">63572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ijoomla" name="com_news_portal">
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1313" published="2010-04-08" name="CVE-2010-1313" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39237" source="BID">39237</ref>
      <ref url="http://www.exploit-db.com/exploits/12082" source="EXPLOIT-DB">12082</ref>
      <ref url="http://secunia.com/advisories/39355" source="SECUNIA" adv="1">39355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seber" name="com_sebercart">
        <vers num="1.0.0.12" />
        <vers num="1.0.0.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1314" published="2010-04-08" name="CVE-2010-1314" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39239" source="BID">39239</ref>
      <ref url="http://www.exploit-db.com/exploits/12086" source="EXPLOIT-DB">12086</ref>
      <ref url="http://secunia.com/advisories/39359" source="SECUNIA" adv="1">39359</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlahsconfig-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlahsconfig-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlanook" name="com_hsconfig">
        <vers num="1.5" />
        <vers num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1315" published="2010-04-08" name="CVE-2010-1315" modified="2010-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57482" source="XF">weberpcutomer-controller-file-include(57482)</ref>
      <ref url="http://www.exploit-db.com/exploits/11999" source="EXPLOIT-DB">11999</ref>
      <ref url="http://secunia.com/advisories/39209" source="SECUNIA" adv="1">39209</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaweberpcustomer-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaweberpcustomer-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlamo" name="com_weberpcustomer">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1316" published="2010-04-14" name="CVE-2010-1316" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Tembria Server Monitor before 5.6.1 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted (1) GET, (2) PUT, or (3) HEAD request, as demonstrated by a malformed GET request containing a long PATH_INFO to index.asp.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.corelan.be:8800/wp-content/forum-file-uploads/admin1/exploits/corelan_lincoln_tembria.py_.txt" source="MISC">http://www.corelan.be:8800/wp-content/forum-file-uploads/admin1/exploits/corelan_lincoln_tembria.py_.txt</ref>
      <ref url="http://www.corelan.be:8800/advisories.php?id=CORELAN-10-022" source="MISC">http://www.corelan.be:8800/advisories.php?id=CORELAN-10-022</ref>
      <ref url="http://secunia.com/advisories/39270" source="SECUNIA" adv="1">39270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tembria" name="server_monitor">
        <vers prev="1" num="5.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1317" published="2010-04-20" name="CVE-2010-1317" modified="2010-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0889" source="VUPEN" adv="1">ADV-2010-0889</ref>
      <ref url="http://www.securityfocus.com/bid/39490" source="BID">39490</ref>
      <ref url="http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf" source="CONFIRM" adv="1">http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf</ref>
      <ref url="http://secunia.com/advisories/39279" source="SECUNIA" adv="1">39279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_dna_server">
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="11.1.2" />
        <vers num="11.1.3" />
        <vers num="12.0" />
        <vers num="13.0" />
      </prod>
      <prod vendor="realnetworks" name="helix_server">
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="12.0.0" />
        <vers num="13.0.0" />
      </prod>
      <prod vendor="realnetworks" name="helix_server_mobile">
        <vers num="11.0" />
        <vers num="12.0.0" />
        <vers num="13.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1318" published="2010-04-20" name="CVE-2010-1318" modified="2010-11-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0889" source="VUPEN" adv="1">ADV-2010-0889</ref>
      <ref url="http://www.securityfocus.com/bid/39490" source="BID">39490</ref>
      <ref url="http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf" source="CONFIRM">http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf</ref>
      <ref url="http://secunia.com/advisories/39279" source="SECUNIA" adv="1">39279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_mobile_server">
        <vers prev="1" num="13.1.1" />
      </prod>
      <prod vendor="realnetworks" name="helix_server">
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="12.0.0" />
        <vers num="12.0.1" />
        <vers prev="1" num="13.1.1" />
      </prod>
      <prod vendor="realnetworks" name="helix_server_mobile">
        <vers num="11.0" />
        <vers num="12.0.0" />
        <vers num="13.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1319" published="2010-04-20" name="CVE-2010-1319" modified="2010-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0889" source="VUPEN" adv="1">ADV-2010-0889</ref>
      <ref url="http://www.securityfocus.com/bid/39490" source="BID">39490</ref>
      <ref url="http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf" source="CONFIRM" adv="1">http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf</ref>
      <ref url="http://secunia.com/advisories/39279" source="SECUNIA" adv="1">39279</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_mobile_server">
        <vers prev="1" num="13.1.1" />
      </prod>
      <prod vendor="realnetworks" name="helix_server">
        <vers num="11.0" />
        <vers num="11.1" />
        <vers num="12.0.0" />
        <vers num="12.0.1" />
        <vers prev="1" num="13.1.1" />
      </prod>
      <prod vendor="realnetworks" name="helix_server_mobile">
        <vers num="11.0" />
        <vers num="12.0.0" />
        <vers num="13.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1320" published="2010-04-22" name="CVE-2010-1320" modified="2010-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1192" source="VUPEN">ADV-2010-1192</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1001" source="VUPEN">ADV-2010-1001</ref>
      <ref url="http://www.ubuntu.com/usn/USN-940-1" source="UBUNTU">USN-940-1</ref>
      <ref url="http://www.securityfocus.com/bid/39599" source="BID">39599</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510843/100/0/threaded" source="BUGTRAQ">20100420 MITKRB5-SA-2010-004 [CVE-2010-1320] double free in KDC</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txt" source="CONFIRM">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-004.txt</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1023904" source="SECTRACK">1023904</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/39784" source="SECUNIA">39784</ref>
      <ref url="http://secunia.com/advisories/39656" source="SECUNIA">39656</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html" source="SUSE">SUSE-SR:2010:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577490" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" />
        <vers num="5-1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1321" published="2010-05-19" name="CVE-2010-1321" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-005.txt

'AFFECTED SOFTWARE
=================

* kadmind and other GSS-API server applications in all known releases
  of MIT krb5, up to and including krb5-1.8.1

* third-party GSS-API server applications that link link against the
  GSS-API library in all known releases of MIT krb5, up to and
  including krb5-1.8.1

* Independent implementations of the krb5 GSS-API mechanism may be
  vulnerable, as the underlying bug is based on plausible (but
  invalid) assumptions about the Kerberos protocol.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-201A.html" source="CERT">TA11-201A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-287A.html" source="CERT">TA10-287A</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511331/100/0/threaded" source="BUGTRAQ" patch="1">20100518 MITKRB5-SA-2010-005 [CVE-2010-1321] GSS-API lib null pointer deref</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-005.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-005.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0134" source="VUPEN">ADV-2011-0134</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3112" source="VUPEN">ADV-2010-3112</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1882" source="VUPEN">ADV-2010-1882</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1574" source="VUPEN">ADV-2010-1574</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1222" source="VUPEN">ADV-2010-1222</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1196" source="VUPEN">ADV-2010-1196</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1193" source="VUPEN">ADV-2010-1193</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1192" source="VUPEN">ADV-2010-1192</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1177" source="VUPEN">ADV-2010-1177</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-940-2" source="UBUNTU">USN-940-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-940-1" source="UBUNTU">USN-940-1</ref>
      <ref url="http://www.securityfocus.com/bid/40235" source="BID">40235</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0880.html" source="REDHAT">RHSA-2011:0880</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0152.html" source="REDHAT">RHSA-2011:0152</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0987.html" source="REDHAT">RHSA-2010:0987</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0935.html" source="REDHAT">RHSA-2010:0935</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0873.html" source="REDHAT">RHSA-2010:0873</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0807.html" source="REDHAT">RHSA-2010:0807</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0770.html" source="REDHAT">RHSA-2010:0770</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0423.html" source="REDHAT">RHSA-2010:0423</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:100" source="MANDRIVA">MDVSA-2010:100</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2052" source="DEBIAN">DSA-2052</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100114315" source="CONFIRM">http://support.avaya.com/css/P8/documents/100114315</ref>
      <ref url="http://secunia.com/advisories/44954" source="SECUNIA">44954</ref>
      <ref url="http://secunia.com/advisories/43335" source="SECUNIA">43335</ref>
      <ref url="http://secunia.com/advisories/42974" source="SECUNIA">42974</ref>
      <ref url="http://secunia.com/advisories/42432" source="SECUNIA">42432</ref>
      <ref url="http://secunia.com/advisories/41967" source="SECUNIA">41967</ref>
      <ref url="http://secunia.com/advisories/40685" source="SECUNIA">40685</ref>
      <ref url="http://secunia.com/advisories/40346" source="SECUNIA">40346</ref>
      <ref url="http://secunia.com/advisories/39849" source="SECUNIA">39849</ref>
      <ref url="http://secunia.com/advisories/39818" source="SECUNIA">39818</ref>
      <ref url="http://secunia.com/advisories/39799" source="SECUNIA">39799</ref>
      <ref url="http://secunia.com/advisories/39784" source="SECUNIA">39784</ref>
      <ref url="http://secunia.com/advisories/39762" source="SECUNIA">39762</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7450" source="OVAL">oval:org.mitre.oval:def:7450</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7198" source="OVAL">oval:org.mitre.oval:def:7198</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11604" source="OVAL">oval:org.mitre.oval:def:11604</ref>
      <ref url="http://osvdb.org/64744" source="OSVDB">64744</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.html" source="SUSE">SUSE-SU-2012:0042</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.html" source="SUSE">SUSE-SU-2012:0010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041654.html" source="FEDORA">FEDORA-2010-8805</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041645.html" source="FEDORA">FEDORA-2010-8796</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041615.html" source="FEDORA">FEDORA-2010-8749</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02257427" source="HP">HPSBUX02544</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02257427" source="HP">HPSBUX02544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="derrick_brashear" name="kadmind">
        <vers num="" />
      </prod>
      <prod vendor="mit" name="kerberos">
        <vers num="5" />
        <vers num="5-1.1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.2.8" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
        <vers num="5-1.4.2" />
        <vers num="5-1.4.3" />
        <vers num="5-1.4.4" />
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.6.3" />
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" edition="alpha" />
        <vers prev="1" num="5-1.8.1" />
        <vers num="5_1.0" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
        <vers num="5_1.2" edition="beta1" />
        <vers num="5_1.2" edition="beta2" />
        <vers num="5_1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1322" published="2010-10-07" name="CVE-2010-1322" modified="2011-01-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request that triggers an uninitialized pointer dereference, as demonstrated by a request from a Windows Active Directory client.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/43756" source="BID" patch="1">43756</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-006.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-006.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2865" source="VUPEN">ADV-2010-2865</ref>
      <ref url="http://www.ubuntu.com/usn/USN-999-1" source="UBUNTU">USN-999-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514144/100/0/threaded" source="BUGTRAQ">20101005 MITKRB5-SA-2010-006 [CVE-2010-1322] KDC uninitialized pointer crash in authorization data handling</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0863.html" source="REDHAT">RHSA-2010:0863</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:202" source="MANDRIVA">MDVSA-2010:202</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.8" />
        <vers num="5-1.8.1" />
        <vers num="5-1.8.2" />
        <vers num="5-1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1323" published="2010-12-02" name="CVE-2010-1323" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visible prompt text, modify a response to a Key Distribution Center (KDC), or forge a KRB-SAFE message via certain checksums that (1) are unkeyed or (2) use RC4 keys.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0187" source="VUPEN">ADV-2011-0187</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3118" source="VUPEN">ADV-2010-3118</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3101" source="VUPEN">ADV-2010-3101</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3095" source="VUPEN">ADV-2010-3095</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3094" source="VUPEN">ADV-2010-3094</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0012.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0012.html</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0007.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0007.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1030-1" source="UBUNTU">USN-1030-1</ref>
      <ref url="http://www.securitytracker.com/id?1024803" source="SECTRACK">1024803</ref>
      <ref url="http://www.securityfocus.com/bid/45118" source="BID">45118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded" source="BUGTRAQ">20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517739/100/0/threaded" source="BUGTRAQ">20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514953/100/0/threaded" source="BUGTRAQ">20101130 MITKRB5-SA-2010-007 Multiple checksum handling vulnerabilities [CVE-2010-1324 CVE-2010-1323 CVE-2010-4020 CVE-2010-4021]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0926.html" source="REDHAT">RHSA-2010:0926</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0925.html" source="REDHAT">RHSA-2010:0925</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:246" source="MANDRIVA">MDVSA-2010:246</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:245" source="MANDRIVA">MDVSA-2010:245</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2129" source="DEBIAN">DSA-2129</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://secunia.com/advisories/46397" source="SECUNIA">46397</ref>
      <ref url="http://secunia.com/advisories/43015" source="SECUNIA">43015</ref>
      <ref url="http://secunia.com/advisories/42436" source="SECUNIA">42436</ref>
      <ref url="http://secunia.com/advisories/42420" source="SECUNIA">42420</ref>
      <ref url="http://secunia.com/advisories/42399" source="SECUNIA" adv="1">42399</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12121" source="OVAL">oval:org.mitre.oval:def:12121</ref>
      <ref url="http://osvdb.org/69610" source="OSVDB">69610</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">HPSBOV02682</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">SSRT100495</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562442714657&amp;w=2" source="HP">SSRT100355</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562442714657&amp;w=2" source="HP">SSRT100355</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2011/000133.html" source="MLIST">[security-announce] 20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00010.html" source="SUSE">SUSE-SU-2012:0042</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00002.html" source="SUSE">SUSE-SU-2012:0010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html" source="SUSE">SUSE-SR:2010:023</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051999.html" source="FEDORA">FEDORA-2010-18425</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051976.html" source="FEDORA">FEDORA-2010-18409</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://kb.vmware.com/kb/1035108" source="CONFIRM">http://kb.vmware.com/kb/1035108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
        <vers num="5-1.4.2" />
        <vers num="5-1.4.3" />
        <vers num="5-1.4.4" />
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.5.4" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" />
        <vers num="5-1.8.1" />
        <vers num="5-1.8.2" />
        <vers num="5-1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1324" published="2010-12-02" name="CVE-2010-1324" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have unspecified other impact via (1) an unkeyed checksum, (2) an unkeyed PAC checksum, or (3) a KrbFastArmoredReq checksum based on an RC4 key.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0187" source="VUPEN">ADV-2011-0187</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3118" source="VUPEN">ADV-2010-3118</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3095" source="VUPEN">ADV-2010-3095</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3094" source="VUPEN">ADV-2010-3094</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0007.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0007.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1030-1" source="UBUNTU">USN-1030-1</ref>
      <ref url="http://www.securitytracker.com/id?1024803" source="SECTRACK">1024803</ref>
      <ref url="http://www.securityfocus.com/bid/45116" source="BID">45116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517739/100/0/threaded" source="BUGTRAQ">20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514953/100/0/threaded" source="BUGTRAQ">20101130 MITKRB5-SA-2010-007 Multiple checksum handling vulnerabilities [CVE-2010-1324 CVE-2010-1323 CVE-2010-4020 CVE-2010-4021]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0925.html" source="REDHAT">RHSA-2010:0925</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:246" source="MANDRIVA">MDVSA-2010:246</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2010-007.txt</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://secunia.com/advisories/43015" source="SECUNIA">43015</ref>
      <ref url="http://secunia.com/advisories/42399" source="SECUNIA" adv="1">42399</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11936" source="OVAL">oval:org.mitre.oval:def:11936</ref>
      <ref url="http://osvdb.org/69609" source="OSVDB">69609</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562442714657&amp;w=2" source="HP">HPSBUX02623</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562442714657&amp;w=2" source="HP">HPSBUX02623</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2011/000133.html" source="MLIST">[security-announce] 20110428 VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html" source="SUSE">SUSE-SR:2010:023</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051999.html" source="FEDORA">FEDORA-2010-18425</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051976.html" source="FEDORA">FEDORA-2010-18409</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://kb.vmware.com/kb/1035108" source="CONFIRM">http://kb.vmware.com/kb/1035108</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7" />
        <vers num="5-1.7.1" />
        <vers num="5-1.8" />
        <vers num="5-1.8.1" />
        <vers num="5-1.8.2" />
        <vers num="5-1.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1325" published="2010-09-03" name="CVE-2010-1325" modified="2010-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the apache2-slms package in SUSE Lifecycle Management Server (SLMS) 1.0 on SUSE Linux Enterprise (SLE) 11 allows remote attackers to hijack the authentication of unspecified victims via vectors related to improper parameter quoting.  NOTE: some sources report that this is a vulnerability in a product named "Apache SLMS," but that is incorrect.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=588284" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=588284</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/61006" source="XF">apacheslms-quoting-csrf(61006)</ref>
      <ref url="http://www.securityfocus.com/bid/42121" source="BID">42121</ref>
      <ref url="http://support.novell.com/security/cve/CVE-2010-1325.html" source="CONFIRM">http://support.novell.com/security/cve/CVE-2010-1325.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="suse_lifecycle_management_server">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1326" published="2010-09-15" name="CVE-2010-1326" modified="2011-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary modules and directories within CVSROOT, and execute arbitrary code via a crafted branch name ACL, possibly related to incorrect inheritance.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/2350" source="VUPEN" adv="1">ADV-2010-2350</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2108" source="DEBIAN">DSA-2108</ref>
      <ref url="http://secunia.com/advisories/41358" source="SECUNIA" adv="1">41358</ref>
      <ref url="http://secunia.com/advisories/41345" source="SECUNIA" adv="1">41345</ref>
      <ref url="http://march-hare.com/cvspro/vuln.htm" source="CONFIRM" adv="1">http://march-hare.com/cvspro/vuln.htm</ref>
      <ref url="http://customer.march-hare.com/webtools/bugzilla/attachment.cgi?tt=1&amp;id=1790&amp;action=view" source="MISC">http://customer.march-hare.com/webtools/bugzilla/attachment.cgi?tt=1&amp;id=1790&amp;action=view</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=593884" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=593884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="march-hare" name="cvs_suite">
        <vers num="2.5.03" />
        <vers num="2008" />
        <vers num="2009" edition="pre-release" />
      </prod>
      <prod vendor="march-hare" name="cvsnt">
        <vers num="2.0.58" />
        <vers num="2.5.01" />
        <vers num="2.5.02" />
        <vers num="2.5.03" />
        <vers num="2.5.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1327" published="2010-07-06" name="CVE-2010-1327" modified="2010-07-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59950" source="XF">tornadostore-precios-sql-injection(59950)</ref>
      <ref url="http://www.securityfocus.com/bid/41233" source="BID">41233</ref>
      <ref url="http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-sql-injection-0106.php" source="MISC">http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-sql-injection-0106.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tornadostore" name="tornadostore">
        <vers prev="1" num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1328" published="2010-07-06" name="CVE-2010-1328" modified="2010-07-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tipo or (2) destino parameter to login_registrese.php3 in the Services section, (3) the rubro parameter to precios.php3 in the Products section, (4) the arti parameter to recomenda_articulo.php3 in the Products section, (5) the descrip parameter in a profile action to control/abm_det.php3 in the e-Commerce section, (6) the tit parameter in a delivery_courier action to control/abm_list.php3 in the e-Commerce section, or (7) the tit parameter in an usuario action to control/abm_det.php3 in the e-Commerce section.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59951" source="XF">tornadostore-multiple-xss(59951)</ref>
      <ref url="http://www.securityfocus.com/bid/41233" source="BID">41233</ref>
      <ref url="http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-xss-0107.php" source="MISC">http://www.bonsai-sec.com/en/research/vulnerabilities/tornadostore-multiple-xss-0107.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tornadostore" name="tornadostore">
        <vers prev="1" num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1329" published="2010-04-15" name="CVE-2010-1329" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion-prevention functionality via a request that has an appended long string containing an unspecified manipulation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.imperva.com/resources/adc/adc_advisories_response_clearskies.html" source="CONFIRM" patch="1" adv="1">http://www.imperva.com/resources/adc/adc_advisories_response_clearskies.html</ref>
      <ref url="http://www.securityfocus.com/bid/39472" source="BID">39472</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510709/100/0/threaded" source="BUGTRAQ">20100413 Imperva SecureSphere Web Application Firewall and Database Firewall Bypass Vulnerability</ref>
      <ref url="http://www.clearskies.net/documents/css-advisory-css1001-imperva.php" source="MISC">http://www.clearskies.net/documents/css-advisory-css1001-imperva.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imperva" name="securesphere_database_firewall">
        <vers num="5.0.0.5082" />
        <vers num="6.0.4.6128" />
        <vers num="6.0.5.6230" />
        <vers num="6.0.5.6238" />
        <vers num="6.0.6.6274" />
        <vers num="6.0.6.6302" />
        <vers num="6.2.0.6442" />
        <vers num="6.2.0.6463" />
        <vers num="7.0.0.7061" />
        <vers num="7.0.0.7078" />
      </prod>
      <prod vendor="imperva" name="securesphere_web_application_firewall">
        <vers num="5.0.0.5082" />
        <vers num="6.0.4.6128" />
        <vers num="6.0.5.6230" />
        <vers num="6.0.5.6238" />
        <vers num="6.0.6.6274" />
        <vers num="6.0.6.6302" />
        <vers num="6.2.0.6442" />
        <vers num="6.2.0.6463" />
        <vers num="7.0.0.7061" />
        <vers num="7.0.0.7078" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1331" published="2010-04-09" name="CVE-2010-1331" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Heartlogic HL-SiteManager allows remote attackers to execute arbitrary SQL commands via unknown vectors.</descript>
      <descript source="nvd">Per: http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000010.html

'[Do not use HL-SiteManager]
    As patches will not be provided, users are recommended to discontinue use of HL-SiteManager and switch to a different product that provides equivalent functionality. '</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57495" source="XF">hlsitemanger-unspecified-sql-injection(57495)</ref>
      <ref url="http://www.heartlogic.jp/docs/free_cgi/hl-sitemanager.html" source="CONFIRM" adv="1">http://www.heartlogic.jp/docs/free_cgi/hl-sitemanager.html</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000010.html" source="JVNDB">JVNDB-2010-000010</ref>
      <ref url="http://jvn.jp/en/jp/JVN60969543/index.html" source="JVN">JVN#60969543</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heartlogic" name="hl-sitemanager">
        <vers num="0.50" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1332" published="2010-04-09" name="CVE-2010-1332" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in PrettyBook PrettyFormMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
      <descript source="nvd">Per: http://jvndb.jvn.jp/en/contents/2010/JVNDB-2010-000007.html

'Solution
    [Do not use PrettyFormMail]
    As patches will not be provided, users are recommended to discontinue use of PrettyFormMail and switch to a different product that provides equivalent functionality. '</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57492" source="XF">prettyformmail-unspecified-xss(57492)</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000007.html" source="JVNDB">JVNDB-2010-000007</ref>
      <ref url="http://jvn.jp/en/jp/JVN41842181/index.html" source="JVN">JVN#41842181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prettybook" name="prettyformmail">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1333" published="2010-04-09" name="CVE-2010-1333" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Almas Inc. Compiere J300_A02 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.compiere-japan.com/products/release/patch.html" source="CONFIRM" patch="1" adv="1">http://www.compiere-japan.com/products/release/patch.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57494" source="XF">compiere-unspec-xss(57494)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57493" source="XF">compiere-unspecified-xss(57493)</ref>
      <ref url="http://secunia.com/advisories/39177" source="SECUNIA" adv="1">39177</ref>
      <ref url="http://osvdb.org/63419" source="OSVDB">63419</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000009.html" source="JVNDB">JVNDB-2010-000009</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000008.html" source="JVNDB">JVNDB-2010-000008</ref>
      <ref url="http://jvn.jp/en/jp/JVN57963254/index.html" source="JVN">JVN#57963254</ref>
      <ref url="http://jvn.jp/en/jp/JVN38687002/index.html" source="JVN">JVN#38687002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="almas" name="compiere">
        <vers num="j253b_a02" />
        <vers num="j300_a01" />
        <vers prev="1" num="j300_a02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1334" published="2010-04-09" name="CVE-2010-1334" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in an unspecified directory, a different vulnerability than CVE-2010-0993.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/434.html

'CWE-434: Unrestricted Upload of File with Dangerous Type'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39046" source="SECUNIA" adv="1">39046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulsecms" name="pulse_cms">
        <vers num="1.2.4" edition="-" />
        <vers num="1.2.4" edition="-:basic" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1335" published="2010-04-09" name="CVE-2010-1335" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3) message2.send/message.send.php, (4) message.send/message.send.php, and (5) pages.add/pages.add.php in insky/modules/.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57112" source="XF">inksky-root-file-include(57112)</ref>
      <ref url="http://www.exploit-db.com/exploits/11848" source="EXPLOIT-DB">11848</ref>
      <ref url="http://secunia.com/advisories/39112" source="SECUNIA" adv="1">39112</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/inskycms-rfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/inskycms-rfi.txt</ref>
      <ref url="http://osvdb.org/63153" source="OSVDB">63153</ref>
      <ref url="http://osvdb.org/63152" source="OSVDB">63152</ref>
      <ref url="http://osvdb.org/63151" source="OSVDB">63151</ref>
      <ref url="http://osvdb.org/63150" source="OSVDB">63150</ref>
      <ref url="http://osvdb.org/63149" source="OSVDB">63149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miftahovn" name="insky_cms">
        <vers num="006-0111" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1336" published="2010-04-09" name="CVE-2010-1336" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57162" source="XF">invohost-manuals-sql-injection(57162)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57161" source="XF">invohost-site-sql-injection(57161)</ref>
      <ref url="http://www.securityfocus.com/bid/38962" source="BID">38962</ref>
      <ref url="http://www.exploit-db.com/exploits/11874" source="EXPLOIT-DB">11874</ref>
      <ref url="http://secunia.com/advisories/39095" source="SECUNIA" adv="1">39095</ref>
      <ref url="http://osvdb.org/63158" source="OSVDB">63158</ref>
      <ref url="http://osvdb.org/63157" source="OSVDB">63157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="invohost" name="invohost">
        <vers num="3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1337" published="2010-04-09" name="CVE-2010-1337" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57147" source="XF">vanilla-definitions-file-include(57147)</ref>
      <ref url="http://www.securityfocus.com/bid/38889" source="BID">38889</ref>
      <ref url="http://www.packetstormsecurity.com/1003-exploits/vanilla-rfi.txt" source="MISC">http://www.packetstormsecurity.com/1003-exploits/vanilla-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lussumo" name="vanilla">
        <vers num="0.9.2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.10" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="a" />
        <vers num="1.1.5" edition="rc1" />
        <vers num="1.1.6" edition="rc2" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1338" published="2010-04-09" name="CVE-2010-1338" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57066" source="XF">wbb-teamsitehack-userid-sql-injection(57066)</ref>
      <ref url="http://www.securityfocus.com/bid/38870" source="BID">38870</ref>
      <ref url="http://www.exploit-db.com/exploits/11824" source="EXPLOIT-DB">11824</ref>
      <ref url="http://secunia.com/advisories/39009" source="SECUNIA" adv="1">39009</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/woltlabb-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/woltlabb-sql.txt</ref>
      <ref url="http://osvdb.org/63126" source="OSVDB">63126</ref>
      <ref url="http://445544.44.ohost.de/worldlabburningboardadon2python-1.txt" source="MISC">http://445544.44.ohost.de/worldlabburningboardadon2python-1.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/03/22/woltlab-burning-board-teamsite-hack-v3-0-ts_other-php-sql-injection-exploit-2/" source="MISC">http://4004securityproject.wordpress.com/2010/03/22/woltlab-burning-board-teamsite-hack-v3-0-ts_other-php-sql-injection-exploit-2/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robertotto" name="teamsite_hack_plugin">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1339" published="2010-04-09" name="CVE-2010-1339" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a modboard action, which is not properly handled in a forced SQL error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39009" source="SECUNIA" adv="1">39009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robertotto" name="teamsite_hack_plugin">
        <vers prev="1" num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1340" published="2010-04-09" name="CVE-2010-1340" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57123" source="XF">jresearch-controller-file-include(57123)</ref>
      <ref url="http://www.securityfocus.com/bid/38917" source="BID">38917</ref>
      <ref url="http://secunia.com/advisories/39079" source="SECUNIA" adv="1">39079</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomlajresearch-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomlajresearch-lfi.txt</ref>
      <ref url="http://osvdb.org/63147" source="OSVDB">63147</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla-research" name="com_jresearch">
        <vers num="1.1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1341" published="2010-04-09" name="CVE-2010-1341" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56861" source="XF">blackforum-index-sql-injection(56861)</ref>
      <ref url="http://www.osvdb.org/62920" source="OSVDB">62920</ref>
      <ref url="http://www.exploit-db.com/exploits/11715" source="EXPLOIT-DB">11715</ref>
      <ref url="http://secunia.com/advisories/38960" source="SECUNIA" adv="1">38960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemsoftware" name="community_black_forum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1342" published="2010-04-09" name="CVE-2010-1342" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and the adminroot parameter to (3) admin/media/update_content.php and (4) library/class.backup.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38975" source="BID">38975</ref>
      <ref url="http://www.exploit-db.com/exploits/11882" source="EXPLOIT-DB">11882</ref>
      <ref url="http://secunia.com/advisories/39106" source="SECUNIA" adv="1">39106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="directnews" name="direct_news">
        <vers num="4.10.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1343" published="2010-04-09" name="CVE-2010-1343" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57173" source="XF">sitexcms-photo-sql-injection(57173)</ref>
      <ref url="http://www.securityfocus.com/bid/38976" source="BID">38976</ref>
      <ref url="http://www.exploit-db.com/exploits/11881" source="EXPLOIT-DB">11881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bjsintay" name="sitex">
        <vers num="0.7.4" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1344" published="2010-04-09" name="CVE-2010-1344" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38785" source="BID" patch="1">38785</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56988" source="XF">ckforms-index-sql-injection(56988)</ref>
      <ref url="http://www.osvdb.org/63032" source="OSVDB">63032</ref>
      <ref url="http://www.exploit-db.com/exploits/11785" source="EXPLOIT-DB">11785</ref>
      <ref url="http://secunia.com/advisories/38976" source="SECUNIA" adv="1">38976</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomlackforms-lfisql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomlackforms-lfisql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cookex" name="com_ckforms">
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1345" published="2010-04-09" name="CVE-2010-1345" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/63031" source="OSVDB">63031</ref>
      <ref url="http://www.exploit-db.com/exploits/11785" source="EXPLOIT-DB">11785</ref>
      <ref url="http://secunia.com/advisories/38976" source="SECUNIA" adv="1">38976</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomlackforms-lfisql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomlackforms-lfisql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cookex" name="com_ckforms">
        <vers num="1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1346" published="2010-04-09" name="CVE-2010-1346" modified="2010-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57092" source="XF">minicmsribafs-login-sqli-injection(57092)</ref>
      <ref url="http://www.securityfocus.com/bid/38881" source="BID">38881</ref>
      <ref url="http://www.exploit-db.com/exploits/11835" source="EXPLOIT-DB">11835</ref>
      <ref url="http://secunia.com/advisories/39018" source="SECUNIA" adv="1">39018</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/minicmsribafs-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/minicmsribafs-sql.txt</ref>
      <ref url="http://osvdb.org/63121" source="OSVDB">63121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ribafs" name="mini_cms_ribafs">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1347" published="2010-04-12" name="CVE-2010-1347" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57611" source="XF">systems-director-agent-sec-bypass(57611)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0830" source="VUPEN" adv="1">ADV-2010-0830</ref>
      <ref url="http://www.securitytracker.com/id?1023831" source="SECTRACK">1023831</ref>
      <ref url="http://www.securityfocus.com/bid/39305" source="BID">39305</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1PM08236" source="AIXAPAR" adv="1">PM08236</ref>
      <ref url="http://secunia.com/advisories/39194" source="SECUNIA" adv="1">39194</ref>
      <ref url="http://osvdb.org/63595" source="OSVDB">63595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="director_agent">
        <vers num="6.1" />
        <vers num="6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1348" published="2010-04-12" name="CVE-2010-1348" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0829" source="VUPEN" patch="1" adv="1">ADV-2010-0829</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM08667" source="AIXAPAR" patch="1" adv="1">PM08667</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57613" source="XF">websphere-login-unspecified(57613)</ref>
      <ref url="http://www.securitytracker.com/id?1023830" source="SECTRACK">1023830</ref>
      <ref url="http://www.securityfocus.com/bid/39306" source="BID">39306</ref>
      <ref url="http://secunia.com/advisories/39305" source="SECUNIA" adv="1">39305</ref>
      <ref url="http://osvdb.org/63594" source="OSVDB">63594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="6.0.1.1" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1349" published="2010-04-12" name="CVE-2010-1349" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://my.opera.com/securitygroup/blog/2010/03/09/the-malformed-content-length-header-security-issue

'We also determined that the problem only existed in our Windows version. '</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0529" source="VUPEN" patch="1" adv="1">ADV-2010-0529</ref>
      <ref url="http://www.securityfocus.com/bid/38519" source="BID" patch="1">38519</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56673" source="XF">opera-contentlength-bo(56673)</ref>
      <ref url="http://www.securitytracker.com/id?1023690" source="SECTRACK">1023690</ref>
      <ref url="http://www.opera.com/support/kb/view/948/" source="CONFIRM" adv="1">http://www.opera.com/support/kb/view/948/</ref>
      <ref url="http://www.exploit-db.com/exploits/11622" source="EXPLOIT-DB">11622</ref>
      <ref url="http://secunia.com/advisories/38820" source="SECUNIA" adv="1">38820</ref>
      <ref url="http://osvdb.org/62714" source="OSVDB">62714</ref>
      <ref url="http://my.opera.com/securitygroup/blog/2010/03/09/the-malformed-content-length-header-security-issue" source="CONFIRM" adv="1">http://my.opera.com/securitygroup/blog/2010/03/09/the-malformed-content-length-header-security-issue</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="10.10" />
        <vers num="10.50" edition="beta_1" />
        <vers num="10.50" edition="beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1350" published="2010-04-12" name="CVE-2010-1350" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39191" source="BID" patch="1">39191</ref>
      <ref url="http://www.joomlanetprojects.com/index.php/en/joomla-projects-downloads/joomla-1/joomla-1/38-comjpjobs.html" source="CONFIRM" patch="1">http://www.joomlanetprojects.com/index.php/en/joomla-projects-downloads/joomla-1/joomla-1/38-comjpjobs.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57500" source="XF">jpjobs-index-sql-injection(57500)</ref>
      <ref url="http://www.xenuser.org/documents/security/joomla_com_jp_jobs_sql.txt" source="MISC">http://www.xenuser.org/documents/security/joomla_com_jp_jobs_sql.txt</ref>
      <ref url="http://www.exploit-db.com/exploits/12037" source="EXPLOIT-DB">12037</ref>
      <ref url="http://secunia.com/advisories/39325" source="SECUNIA" adv="1">39325</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajpjobs-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajpjobs-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlaprojects" name="com_jp_jobs">
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers prev="1" num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1351" published="2010-04-12" name="CVE-2010-1351" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to erase_user_data.php and the (2) _nodesforum_code_path parameter to pre_output.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57517" source="XF">nodesforum-preoutput-file-include(57517)</ref>
      <ref url="http://www.exploit-db.com/exploits/12047" source="EXPLOIT-DB">12047</ref>
      <ref url="http://secunia.com/advisories/39311" source="SECUNIA" adv="1">39311</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nodesforum" name="nodesforum">
        <vers num="1.033" />
        <vers num="1.045" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1352" published="2010-04-12" name="CVE-2010-1352" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39248" source="BID">39248</ref>
      <ref url="http://www.exploit-db.com/exploits/12084" source="EXPLOIT-DB">12084</ref>
      <ref url="http://secunia.com/advisories/39357" source="SECUNIA" adv="1">39357</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajukebox-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajukebox-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jooforge" name="com_jukebox">
        <vers num="1.0" />
        <vers num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1353" published="2010-04-12" name="CVE-2010-1353" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57533" source="XF">comloginbox-view-file-include(57533)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0808" source="VUPEN" adv="1">ADV-2010-0808</ref>
      <ref url="http://www.securityfocus.com/bid/39212" source="BID">39212</ref>
      <ref url="http://www.exploit-db.com/exploits/12068" source="EXPLOIT-DB">12068</ref>
      <ref url="http://secunia.com/advisories/39349" source="SECUNIA" adv="1">39349</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaloginbox-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaloginbox-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wowjoomla" name="com_loginbox">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1354" published="2010-04-12" name="CVE-2010-1354" modified="2010-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39266" source="BID">39266</ref>
      <ref url="http://www.exploit-db.com/exploits/12102" source="EXPLOIT-DB">12102</ref>
      <ref url="http://secunia.com/advisories/39296" source="SECUNIA" adv="1">39296</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlavjdeo-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlavjdeo-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ternaria" name="com_vjdeo">
        <vers num="1.0" />
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1355" published="2010-04-13" name="CVE-2010-1355" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Reference ID 66316.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ftp.tandberg.com/pub/software/vcs/TANDBERG%20Video%20Communication%20Server%20Software%20Release%20Notes%20%28X5%29.pdf" source="CONFIRM">http://ftp.tandberg.com/pub/software/vcs/TANDBERG%20Video%20Communication%20Server%20Software%20Release%20Notes%20(X5).pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vsecurity" name="tandberg_video_communication_server">
        <vers num="x1.0.0" />
        <vers num="x1.1.0" />
        <vers num="x1.2.0" />
        <vers num="x2.0.0" />
        <vers num="x2.1.0" />
        <vers num="x3.0.0" />
        <vers num="x3.1.0" />
        <vers num="x4.1.0" />
        <vers num="x4.2.0" />
        <vers num="x4.2.1" />
        <vers prev="1" num="x4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1356" published="2010-04-13" name="CVE-2010-1356" modified="2010-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to execute arbitrary code via unknown vectors, aka Reference ID 69773.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ftp.tandberg.com/pub/software/vcs/TANDBERG%20Video%20Communication%20Server%20Software%20Release%20Notes%20%28X5%29.pdf" source="CONFIRM">http://ftp.tandberg.com/pub/software/vcs/TANDBERG%20Video%20Communication%20Server%20Software%20Release%20Notes%20(X5).pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vsecurity" name="tandberg_video_communication_server">
        <vers num="x1.0.0" />
        <vers num="x1.1.0" />
        <vers num="x1.2.0" />
        <vers num="x2.0.0" />
        <vers num="x2.1.0" />
        <vers num="x3.0.0" />
        <vers num="x3.1.0" />
        <vers num="x4.1.0" />
        <vers num="x4.2.0" />
        <vers num="x4.2.1" />
        <vers prev="1" num="x4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1357" published="2010-04-13" name="CVE-2010-1357" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in editors/logindialogue.php in SBD Directory Software 4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55564" source="XF">sbddirectory-logindialogue-xss(55564)</ref>
      <ref url="http://www.osvdb.org/61659" source="OSVDB">61659</ref>
      <ref url="http://www.exploit-db.com/exploits/11118" source="EXPLOIT-DB">11118</ref>
      <ref url="http://secunia.com/advisories/38148" source="SECUNIA" adv="1">38148</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/sbddirectory-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/sbddirectory-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sbddirectorysoftware" name="sbd_directory_software">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1358" published="2010-04-13" name="CVE-2010-1358" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37804" source="BID" patch="1">37804</ref>
      <ref url="http://drupal.org/node/683786" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/683786</ref>
      <ref url="http://secunia.com/advisories/38207" source="SECUNIA" adv="1">38207</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ron_jerome" name="bibliography">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="5.x-1.4" />
        <vers num="5.x-1.5" />
        <vers num="5.x-1.6" />
        <vers num="5.x-1.7" />
        <vers num="5.x-1.x-dev" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.0" edition="rc2" />
        <vers num="6.x-1.0" edition="rc3" />
        <vers num="6.x-1.0" edition="rc4" />
        <vers num="6.x-1.0" edition="rc5" />
        <vers num="6.x-1.0-beta1" />
        <vers num="6.x-1.0-beta2" />
        <vers num="6.x-1.0-beta3" />
        <vers num="6.x-1.0-beta4" />
        <vers num="6.x-1.0-beta5" />
        <vers num="6.x-1.0-beta6" />
        <vers num="6.x-1.0-beta7" />
        <vers num="6.x-1.0-beta8" />
        <vers num="6.x-1.0-beta9" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.5" />
        <vers num="6.x-1.6" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1359" published="2010-04-13" name="CVE-2010-1359" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in bluegate_seo.inc.php in the Direct URL module for xt:Commerce, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the coID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37808" source="BID">37808</ref>
      <ref url="http://secunia.com/advisories/38197" source="SECUNIA" adv="1">38197</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluegate" name="direct_url">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1360" published="2010-04-13" name="CVE-2010-1360" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55532" source="XF">faqengine-pathfaqe-file-include(55532)</ref>
      <ref url="http://www.securityfocus.com/bid/37719" source="BID">37719</ref>
      <ref url="http://www.exploit-db.com/exploits/11111" source="EXPLOIT-DB">11111</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/faqengine-rfi.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/faqengine-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boesch-it" name="faqengine">
        <vers num="4.24.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1361" published="2010-04-13" name="CVE-2010-1361" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/37707" source="BID" patch="1">37707</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55561" source="XF">phpeppershop-darstellen-xss(55561)</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/phpeppershopws-xss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/phpeppershopws-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glarotech" name="phpeppershop">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1362" published="2010-04-13" name="CVE-2010-1362" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Own Term module 6.x-1.0 for Drupal allows remote authenticated users, with "create additional terms" privileges, to inject arbitrary web script or HTML via the term description field in a term listing page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/683576" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/683576</ref>
      <ref url="http://drupal.org/node/683544" source="CONFIRM" patch="1">http://drupal.org/node/683544</ref>
      <ref url="http://www.securityfocus.com/bid/37788" source="BID">37788</ref>
      <ref url="http://secunia.com/advisories/38208" source="SECUNIA" adv="1">38208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ben_jeavons" name="ownterm">
        <vers num="6.x-1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1363" published="2010-04-13" name="CVE-2010-1363" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55361" source="XF">jprojects-index-sql-injection(55361)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0049" source="VUPEN" adv="1">ADV-2010-0049</ref>
      <ref url="http://www.securityfocus.com/bid/37608" source="BID">37608</ref>
      <ref url="http://www.exploit-db.com/exploits/10988" source="EXPLOIT-DB">10988</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/joomlajprojects-sql.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/joomlajprojects-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extremejoomla" name="com_j-projects">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1364" published="2010-04-13" name="CVE-2010-1364" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0488" source="VUPEN" adv="1">ADV-2010-0488</ref>
      <ref url="http://www.exploit-db.com/exploits/11599" source="EXPLOIT-DB">11599</ref>
      <ref url="http://secunia.com/advisories/38757" source="SECUNIA" adv="1">38757</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/uigapersonalportal-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/uigapersonalportal-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="personal_portal">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1365" published="2010-04-13" name="CVE-2010-1365" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0487" source="VUPEN" adv="1">ADV-2010-0487</ref>
      <ref url="http://www.exploit-db.com/exploits/11600" source="EXPLOIT-DB">11600</ref>
      <ref url="http://secunia.com/advisories/38756" source="SECUNIA" adv="1">38756</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/uigafc-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/uigafc-sql.txt</ref>
      <ref url="http://4004securityproject.wordpress.com/2010/02/28/uigafanclub-index-php-sql-injection/" source="MISC">http://4004securityproject.wordpress.com/2010/02/28/uigafanclub-index-php-sql-injection/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="fan_club">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1366" published="2010-04-13" name="CVE-2010-1366" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/11593" source="EXPLOIT-DB">11593</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/uigafanclub-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/uigafanclub-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="fan_club">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1367" published="2010-04-13" name="CVE-2010-1367" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin/admin_login.php in Uiga Fan Club, as downloaded on 20100310, allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name and (2) admin_password parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38756" source="SECUNIA" adv="1">38756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="fan_club">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1368" published="2010-04-13" name="CVE-2010-1368" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56537" source="XF">gamescript-index-sql-injection(56537)</ref>
      <ref url="http://www.securityfocus.com/bid/38414" source="BID">38414</ref>
      <ref url="http://www.exploit-db.com/exploits/11577" source="EXPLOIT-DB">11577</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/gamescript-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/gamescript-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamescript" name="gamescript">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1369" published="2010-04-13" name="CVE-2010-1369" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38446" source="BID">38446</ref>
      <ref url="http://www.exploit-db.com/exploits/11589" source="EXPLOIT-DB">11589</ref>
      <ref url="http://secunia.com/advisories/38768" source="SECUNIA" adv="1">38768</ref>
      <ref url="http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt" source="MISC">http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="preprojects" name="pre_classified_listings_asp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1370" published="2010-04-13" name="CVE-2010-1370" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38768" source="SECUNIA" adv="1">38768</ref>
      <ref url="http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt" source="MISC">http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="preprojects" name="pre_classified_listings_asp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1371" published="2010-04-13" name="CVE-2010-1371" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38768" source="SECUNIA" adv="1">38768</ref>
      <ref url="http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt" source="MISC">http://packetstormsecurity.org/0812-exploits/preclass-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="preprojects" name="pre_classified_listings_asp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1372" published="2010-04-13" name="CVE-2010-1372" modified="2010-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56516" source="XF">hdflvplayer-index-sql-injection(56516)</ref>
      <ref url="http://www.securityfocus.com/bid/38401" source="BID">38401</ref>
      <ref url="http://secunia.com/advisories/38691" source="SECUNIA" adv="1">38691</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/joomlahdflvplayer-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/joomlahdflvplayer-sql.txt</ref>
      <ref url="http://osvdb.org/62570" source="OSVDB">62570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hdflvplayer" name="com_hdflvplayer">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1373" published="2010-06-17" name="CVE-2010-1373" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" patch="1" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1374" published="2010-06-17" name="CVE-2010-1374" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1375" published="2010-06-17" name="CVE-2010-1375" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1376" published="2010-06-17" name="CVE-2010-1376" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) afp, (2) cifs, or (3) smb URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1377" published="2010-06-17" name="CVE-2010-1377" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1378" published="2010-11-15" name="CVE-2010-1378" modified="2010-11-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1379" published="2010-06-17" name="CVE-2010-1379" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1380" published="2010-06-17" name="CVE-2010-1380" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page sizes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1381" published="2010-06-17" name="CVE-2010-1381" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links.  NOTE: this might overlap CVE-2010-0926.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1382" published="2010-06-17" name="CVE-2010-1382" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1383" published="2011-07-21" name="CVE-2010-1383" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cfnetwork">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.3" edition="417.9.3" />
        <vers num="2.0.4" />
        <vers num="3" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.0b" />
        <vers num="3.0.1" />
        <vers num="3.0.1b" />
        <vers num="3.0.2" />
        <vers num="3.0.2b" />
        <vers num="3.0.3" />
        <vers num="3.0.3b" />
        <vers num="3.0.4" />
        <vers num="3.0.4b" />
        <vers num="3.1.0" />
        <vers num="3.1.0b" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers prev="1" num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1384" published="2010-06-11" name="CVE-2010-1384" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6812" source="OVAL">oval:org.mitre.oval:def:6812</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001538.html" source="JVNDB">JVNDB-2010-001538</ref>
      <ref url="http://jvn.jp/en/jp/JVN46026251/index.html" source="JVN">JVN#46026251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1385" published="2010-06-11" name="CVE-2010-1385" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7199" source="OVAL">oval:org.mitre.oval:def:7199</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1386" published="2010-08-19" name="CVE-2010-1386" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=36255" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=36255</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/42500" source="BID">42500</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/56188" source="CONFIRM">http://trac.webkit.org/changeset/56188</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1386" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1386</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="r50173" />
        <vers prev="1" num="r56187" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1387" published="2010-06-18" name="CVE-2010-1387" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59506" source="XF">itunes-webkit-unspecified-var1(59506)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://securitytracker.com/id?1024108" source="SECTRACK">1024108</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7061" source="OVAL">oval:org.mitre.oval:def:7061</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" edition="" />
        <vers num="7.6.2" edition=":windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:windows" />
        <vers num="8.0" edition="-" />
        <vers num="8.0" edition="-:windows" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:windows" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:windows" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:windows" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:windows" />
        <vers num="8.1.1" edition="-" />
        <vers num="8.1.1" edition="-:windows" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:windows" />
        <vers num="8.2.1" edition="-" />
        <vers num="8.2.1" edition="-:windows" />
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers num="9.0.3" edition="-" />
        <vers num="9.0.3" edition="-:windows" />
        <vers num="9.1" edition="-" />
        <vers num="9.1" edition="-:windows" />
        <vers prev="1" num="9.1.1" edition="-" />
        <vers prev="1" num="9.1.1" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1388" published="2010-06-11" name="CVE-2010-1388" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/40752" source="BID">40752</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1389" published="2010-06-11" name="CVE-2010-1389" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) paste or (2) drag-and-drop operation for a selection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6649" source="OVAL">oval:org.mitre.oval:def:6649</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1390" published="2010-06-11" name="CVE-2010-1390" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 canonicalization, and lack of termination of a quoted string in an HTML document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6888" source="OVAL">oval:org.mitre.oval:def:6888</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1391" published="2010-06-11" name="CVE-2010-1391" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot dot) in a URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40753" source="BID">40753</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7082" source="OVAL">oval:org.mitre.oval:def:7082</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1392" published="2010-06-11" name="CVE-2010-1392" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to HTML buttons and the first-letter CSS style.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511700/100/0/threaded" source="BUGTRAQ">20100608 VUPEN Security Research - Apple Safari WebKit HTML Button Use-after-free Vulnerability (CVE-2010-1392)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7024" source="OVAL">oval:org.mitre.oval:def:7024</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1393" published="2010-06-11" name="CVE-2010-1393" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to discover sensitive URLs via an HREF attribute associated with a redirecting URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7346" source="OVAL">oval:org.mitre.oval:def:7346</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1394" published="2010-06-11" name="CVE-2010-1394" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document fragments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK" patch="1">1024067</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID">40620</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7552" source="OVAL">oval:org.mitre.oval:def:7552</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1395" published="2010-06-11" name="CVE-2010-1395" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving DOM constructor objects, related to a "scope management issue."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7464" source="OVAL">oval:org.mitre.oval:def:7464</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1396" published="2010-06-11" name="CVE-2010-1396" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the contentEditable attribute and removing container elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-092" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-092</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40647" source="BID">40647</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7288" source="OVAL">oval:org.mitre.oval:def:7288</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1397" published="2010-06-11" name="CVE-2010-1397" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to a layout change during selection rendering and the DOCUMENT_POSITION_DISCONNECTED attribute in a container of an unspecified type.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" patch="1" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-095" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-095</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511721/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-095: Apple Webkit DOCUMENT_POSITION_DISCONNECTED Attribute Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6912" source="OVAL">oval:org.mitre.oval:def:6912</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1398" published="2010-06-11" name="CVE-2010-1398" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an unspecified element into an editable container and the access of an uninitialized element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-097" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-097</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511719/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-097: Apple Webkit ContentEditable moveParagraphs Uninitialized Element Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7556" source="OVAL">oval:org.mitre.oval:def:7556</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1399" published="2010-06-11" name="CVE-2010-1399" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during a selection change on a form input element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6709" source="OVAL">oval:org.mitre.oval:def:6709</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1400" published="2010-06-11" name="CVE-2010-1400" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving caption elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7031" source="OVAL">oval:org.mitre.oval:def:7031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=870" source="IDEFENSE">20100607 Multiple Vendor WebKit HTML Caption Use After Free Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1401" published="2010-06-11" name="CVE-2010-1401" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-098" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-098</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511717/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-098: Apple Webkit First-Letter Pseudo-Element Style Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6981" source="OVAL">oval:org.mitre.oval:def:6981</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1402" published="2010-06-11" name="CVE-2010-1402" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to an event listener in an SVG document, related to duplicate event listeners, a timer, and an AnimateTransform object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-100" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-100</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511723/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-100: Apple Webkit ConditionEventListener Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7071" source="OVAL">oval:org.mitre.oval:def:7071</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1403" published="2010-06-11" name="CVE-2010-1403" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during the handling of a use element in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document containing XML that triggers a parsing error, related to ProcessInstruction.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-099/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-099/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511722/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-099: Apple Webkit ProcessInstruction Target Error Message Insertion Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA" adv="1">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7519" source="OVAL">oval:org.mitre.oval:def:7519</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1404" published="2010-06-11" name="CVE-2010-1404" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-096" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-096</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511718/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-096: Apple Webkit Recursive Use Element Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7497" source="OVAL">oval:org.mitre.oval:def:7497</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1405" published="2010-06-11" name="CVE-2010-1405" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40659" source="BID">40659</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7252" source="OVAL">oval:org.mitre.oval:def:7252</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1406" published="2010-06-11" name="CVE-2010-1406" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging, a related issue to CVE-2010-0660.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7197" source="OVAL">oval:org.mitre.oval:def:7197</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1407" published="2010-06-22" name="CVE-2010-1407" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59629" source="XF">appleios-historyreplace-info-disclosure(59629)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.1" />
        <vers num="2.2.1" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1408" published="2010-06-11" name="CVE-2010-1408" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to bypass intended restrictions on outbound connections to "non-default TCP ports" via a crafted port number, related to an "integer truncation issue." NOTE: this may overlap CVE-2010-1099.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40697" source="BID">40697</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7295" source="OVAL">oval:org.mitre.oval:def:7295</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1409" published="2010-06-11" name="CVE-2010-1409" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to trigger disclosure of data over IRC via vectors involving an IRC service port.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/184.html

'Incomplete Blacklist'</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6836" source="OVAL">oval:org.mitre.oval:def:6836</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1410" published="2010-06-11" name="CVE-2010-1410" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an SVG document with nested use elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40657" source="BID">40657</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7150" source="OVAL">oval:org.mitre.oval:def:7150</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1411" published="2010-06-17" name="CVE-2010-1411" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=592361" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=592361</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1761" source="VUPEN">ADV-2010-1761</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1731" source="VUPEN">ADV-2010-1731</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1435" source="VUPEN">ADV-2010-1435</ref>
      <ref url="http://www.ubuntu.com/usn/USN-954-1" source="UBUNTU">USN-954-1</ref>
      <ref url="http://www.securityfocus.com/bid/40823" source="BID">40823</ref>
      <ref url="http://www.remotesensing.org/libtiff/v3.9.3.html" source="CONFIRM">http://www.remotesensing.org/libtiff/v3.9.3.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0520.html" source="REDHAT">RHSA-2010:0520</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0519.html" source="REDHAT">RHSA-2010:0519</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024103" source="SECTRACK">1024103</ref>
      <ref url="http://secunia.com/advisories/40536" source="SECUNIA">40536</ref>
      <ref url="http://secunia.com/advisories/40527" source="SECUNIA">40527</ref>
      <ref url="http://secunia.com/advisories/40478" source="SECUNIA">40478</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40181" source="SECUNIA">40181</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127731610612908&amp;w=2" source="MLIST">[oss-security] 20100623 CVE requests: LibTIFF</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043835.html" source="FEDORA">FEDORA-2010-10469</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043769.html" source="FEDORA">FEDORA-2010-10460</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1412" published="2010-06-11" name="CVE-2010-1412" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to hover events.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7606" source="OVAL">oval:org.mitre.oval:def:7606</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1413" published="2010-06-11" name="CVE-2010-1413" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in unspecified circumstances, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/40733" source="BID">40733</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7255" source="OVAL">oval:org.mitre.oval:def:7255</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1414" published="2010-06-11" name="CVE-2010-1414" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the removeChild DOM method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7041" source="OVAL">oval:org.mitre.oval:def:7041</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1415" published="2010-06-11" name="CVE-2010-1415" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml contexts, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to an "API abuse issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7374" source="OVAL">oval:org.mitre.oval:def:7374</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1416" published="2010-06-11" name="CVE-2010-1416" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote attackers to read images from other sites via a crafted canvas, related to a "cross-site image capture issue."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7401" source="OVAL">oval:org.mitre.oval:def:7401</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1417" published="2010-06-11" name="CVE-2010-1417" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via HTML content that contains multiple :after pseudo-selectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/40672" source="BID">40672</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6876" source="OVAL">oval:org.mitre.oval:def:6876</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1418" published="2010-06-11" name="CVE-2010-1418" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via a FRAME element with a SRC attribute composed of a javascript: sequence preceded by spaces.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6871" source="OVAL">oval:org.mitre.oval:def:6871</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1419" published="2010-06-11" name="CVE-2010-1419" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a certain window close action that occurs during a drag-and-drop operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7314" source="OVAL">oval:org.mitre.oval:def:7314</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1420" published="2011-07-21" name="CVE-2010-1420" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CFNetwork in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted text/plain file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cfnetwork">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.3" edition="417.9.3" />
        <vers num="2.0.4" />
        <vers num="3" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.0b" />
        <vers num="3.0.1" />
        <vers num="3.0.1b" />
        <vers num="3.0.2" />
        <vers num="3.0.2b" />
        <vers num="3.0.3" />
        <vers num="3.0.3b" />
        <vers num="3.0.4" />
        <vers num="3.0.4b" />
        <vers num="3.1.0" />
        <vers num="3.1.0b" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.0.3" />
        <vers num="5.0.4" />
        <vers prev="1" num="5.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1421" published="2010-06-11" name="CVE-2010-1421" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The execCommand JavaScript function in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict remote execution of clipboard commands, which allows remote attackers to modify the clipboard via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6739" source="OVAL">oval:org.mitre.oval:def:6739</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1422" published="2010-06-11" name="CVE-2010-1422" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=552255" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=552255</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7591" source="OVAL">oval:org.mitre.oval:def:7591</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1423" published="2010-04-15" name="CVE-2010-1423" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/886582" source="CERT-VN">VU#886582</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0853" source="VUPEN" patch="1" adv="1">ADV-2010-0853</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57615" source="XF">jre-toolkit-command-execution(57615)</ref>
      <ref url="http://www.securitytracker.com/id?1023840" source="SECTRACK">1023840</ref>
      <ref url="http://www.reversemode.com/index.php?option=com_content&amp;task=view&amp;id=67&amp;Itemid=1" source="MISC">http://www.reversemode.com/index.php?option=com_content&amp;task=view&amp;id=67&amp;Itemid=1</ref>
      <ref url="http://secunia.com/advisories/39260" source="SECUNIA" adv="1">39260</ref>
      <ref url="http://osvdb.org/63648" source="OSVDB">63648</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2010-April/074036.html" source="FULLDISC">20100409 Java Deployment Toolkit Performs Insufficient Validation of Parameters</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jdk">
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_19" />
      </prod>
      <prod vendor="oracle" name="jre">
        <vers prev="1" num="1.6.0" edition="update_10" />
        <vers prev="1" num="1.6.0" edition="update_19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1424" published="2010-04-15" name="CVE-2010-1424" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government 2006 through 2010 allows user-assisted remote attackers to execute arbitrary code via a crafted font file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0854" source="VUPEN" patch="1" adv="1">ADV-2010-0854</ref>
      <ref url="http://www.justsystems.com/jp/info/js10001.html" source="CONFIRM" patch="1" adv="1">http://www.justsystems.com/jp/info/js10001.html</ref>
      <ref url="http://www.securitytracker.com/id?1023844" source="SECTRACK">1023844</ref>
      <ref url="http://secunia.com/advisories/39256" source="SECUNIA" adv="1">39256</ref>
      <ref url="http://osvdb.org/63651" source="OSVDB">63651</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000015.html" source="JVNDB">JVNDB-2010-000015</ref>
      <ref url="http://jvn.jp/en/jp/JVN98467259/index.html" source="JVN">JVN#98467259</ref>
    </refs>
    <vuln_soft>
      <prod vendor="justsystems" name="ichitaro">
        <vers num="2006" edition="-" />
        <vers num="2006" edition="-:government" />
        <vers num="2007" edition="-" />
        <vers num="2007" edition="-:government" />
        <vers num="2008" edition="-" />
        <vers num="2008" edition="-:government" />
        <vers num="2009" edition="-" />
        <vers num="2009" edition="-:government" />
        <vers num="2009" edition="-:trial" />
        <vers num="2010" edition="-" />
        <vers num="2010" edition="-:trial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1425" published="2010-04-15" name="CVE-2010-1425" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security 8 and earlier, and for E-mail and Server security 9 and earlier; Mac Protection build 8060 and earlier; Client Security 9 and earlier; and various Anti-Virus products for Windows, Linux, and Citrix; does not properly detect malware in crafted (1) 7Z, (2) GZIP, (3) CAB, or (4) RAR archives, which makes it easier for remote attackers to avoid detection.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0855" source="VUPEN" patch="1" adv="1">ADV-2010-0855</ref>
      <ref url="http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html" source="CONFIRM" patch="1" adv="1">http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-1.html</ref>
      <ref url="http://www.securitytracker.com/id?1023843" source="SECTRACK">1023843</ref>
      <ref url="http://www.securitytracker.com/id?1023842" source="SECTRACK">1023842</ref>
      <ref url="http://www.securitytracker.com/id?1023841" source="SECTRACK">1023841</ref>
      <ref url="http://secunia.com/advisories/39396" source="SECUNIA" adv="1">39396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="anti-virus">
        <vers num="6.62" edition="-" />
        <vers num="6.62" edition="-:microsoft_exchange" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:microsoft_exchange" />
        <vers num="7.10" edition="-" />
        <vers num="7.10" edition="-:microsoft_exchange" />
        <vers prev="1" num="9.00" edition="-" />
        <vers prev="1" num="9.00" edition="-:microsoft_exchange" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="" edition=":linux_gateways" />
        <vers num="2.16" edition="" />
        <vers num="2.16" edition=":linux_gateways" />
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" edition="" />
        <vers num="2007" edition=":second" />
        <vers num="2007" edition="second_edition" />
        <vers num="2008" />
        <vers num="2009" />
        <vers prev="1" num="2010" />
        <vers num="4.50" edition="" />
        <vers num="4.50" edition=":linux" />
        <vers num="4.50_hotfix_1" edition="" />
        <vers num="4.50_hotfix_1" edition=":linux" />
        <vers num="4.50_hotfix_2" edition="" />
        <vers num="4.50_hotfix_2" edition=":linux" />
        <vers num="4.51" edition="" />
        <vers num="4.51" edition=":linux_workstations" />
        <vers num="4.51" edition=":linux_servers" />
        <vers num="4.51" edition=":linux_gateways" />
        <vers num="4.51_hotfix_2" edition="" />
        <vers num="4.51_hotfix_2" edition=":linux" />
        <vers num="4.52" edition="" />
        <vers num="4.52" edition=":linux_workstations" />
        <vers num="4.52" edition=":linux" />
        <vers num="4.52" edition=":linux_servers" />
        <vers num="4.52" edition=":linux_gateways" />
        <vers num="4.60" edition="" />
        <vers num="4.60" edition=":samba_servers" />
        <vers num="4.61" edition="" />
        <vers num="4.61" edition=":linux_gateways" />
        <vers num="4.61" edition=":linux_servers" />
        <vers num="4.62" edition="" />
        <vers num="4.62" edition=":samba_servers" />
        <vers num="4.64" edition="" />
        <vers num="4.64" edition=":linux_servers" />
        <vers num="4.64" edition=":linux_gateways" />
        <vers num="4.65" edition="" />
        <vers num="4.65" edition=":linux_servers" />
        <vers num="4.65" edition=":linux_gateways" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":linux_client_security" />
        <vers num="5.0" edition=":linux_server_security" />
        <vers num="5.0.2" />
        <vers num="5.01" edition="" />
        <vers num="5.01" edition=":linux_client_security" />
        <vers num="5.01" edition=":linux_server_security" />
        <vers num="5.11" edition="" />
        <vers num="5.11" edition=":linux_client_security" />
        <vers num="5.11" edition=":linux_server_security" />
        <vers num="5.2.1" />
        <vers num="5.3.0" />
        <vers num="5.40" edition="" />
        <vers num="5.40" edition=":workstations" />
        <vers num="5.41" edition="" />
        <vers num="5.41" edition=":mimesweeper" />
        <vers num="5.41" edition=":windows_servers" />
        <vers num="5.41" edition=":file_servers" />
        <vers num="5.41" edition=":workstations" />
        <vers num="5.42" edition="" />
        <vers num="5.42" edition=":mimesweeper" />
        <vers num="5.42" edition=":file_servers" />
        <vers num="5.42" edition=":windows_servers" />
        <vers num="5.42" edition=":workstations" />
        <vers num="5.43" edition="" />
        <vers num="5.43" edition=":workstations" />
        <vers num="5.44" edition="" />
        <vers num="5.44" edition=":workstations" />
        <vers num="5.5" edition="" />
        <vers num="5.5" edition=":mimesweeper" />
        <vers num="5.5" edition=":citrix_servers" />
        <vers num="5.5" edition=":client_security" />
        <vers num="5.5" edition=":windows_servers" />
        <vers num="5.51" edition="" />
        <vers num="5.51" edition=":mimesweeper" />
        <vers num="5.51" edition=":citrix_servers" />
        <vers num="5.52" edition="" />
        <vers num="5.52" edition=":mimesweeper" />
        <vers num="5.52" edition=":citrix_servers" />
        <vers num="5.52" edition=":client_security" />
        <vers num="5.52" edition=":windows_servers" />
        <vers num="5.54" edition="" />
        <vers num="5.54" edition=":client_security" />
        <vers num="5.55" edition="" />
        <vers num="5.55" edition=":client_security" />
        <vers num="5.56" />
        <vers num="5.61" edition="" />
        <vers num="5.61" edition=":mimesweeper" />
        <vers num="6.01" edition="" />
        <vers num="6.01" edition=":ms_exchange" />
        <vers num="6.01" edition=":client_security" />
        <vers num="6.02" edition="" />
        <vers num="6.02" edition=":client_security" />
        <vers num="6.03" edition="" />
        <vers num="6.03" edition=":client_security" />
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":firewalls" />
        <vers num="6.2" edition=":ms_exchange" />
        <vers num="6.21" edition="" />
        <vers num="6.21" edition=":ms_exchange" />
        <vers num="6.30" edition="" />
        <vers num="6.30" edition=":ms_exchange" />
        <vers num="6.30_sr1" edition="" />
        <vers num="6.30_sr1" edition=":ms_exchange" />
        <vers num="6.31" edition="" />
        <vers num="6.31" edition=":ms_exchange" />
        <vers num="6.40" edition="" />
        <vers num="6.40" edition=":ms_exchange" />
        <vers num="6.60" edition="" />
        <vers num="6.60" edition=":ms_exchange" />
        <vers num="6.61" edition="" />
        <vers num="6.61" edition=":ms_exchange" />
        <vers num="7.00" edition="" />
        <vers num="7.00" edition=":ms_exchange" />
        <vers num="7.00" edition=":workstations" />
        <vers num="7.00" edition=":client_security" />
        <vers num="7.00" edition=":windows_servers" />
        <vers num="7.02" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_client_security">
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="7.01" />
        <vers num="7.10" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_citrix_servers">
        <vers num="7.00" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_linux">
        <vers num="4.65" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_microsoft_exchange">
        <vers num="6.62" />
        <vers num="7.00" />
        <vers num="7.10" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_mimesweeper">
        <vers num="5.61" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_windows_servers">
        <vers num="8.00" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_for_workstations">
        <vers num="5.44" />
        <vers num="7.00" />
        <vers num="7.10" />
        <vers num="7.11" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_linux_client_security">
        <vers num="5.30" />
        <vers num="5.52" />
        <vers num="5.53" />
        <vers num="5.54" />
      </prod>
      <prod vendor="f-secure" name="f-secure_anti-virus_linux_server_security">
        <vers num="5.30" />
        <vers num="5.52" />
        <vers num="5.54" />
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" edition="" />
        <vers num="2007" edition=":second" />
        <vers num="2007" edition="second_edition" />
        <vers num="2008" />
        <vers num="2009" />
        <vers prev="1" num="2010" />
        <vers num="7.02" />
      </prod>
      <prod vendor="f-secure" name="home_server_security">
        <vers num="2009" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers prev="1" num="4.02" edition="-" />
        <vers prev="1" num="4.02" edition="-:linux" />
        <vers prev="1" num="6.61" edition="-" />
        <vers prev="1" num="6.61" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1426" published="2010-04-15" name="CVE-2010-1426" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304" source="CONFIRM" patch="1" adv="1">http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000012.html" source="JVNDB" patch="1">JVNDB-2010-000012</ref>
      <ref url="http://jvn.jp/en/jp/JVN19774883/index.html" source="JVN" patch="1">JVN#19774883</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57636" source="XF">modx-unspecified-sql-injection(57636)</ref>
      <ref url="http://secunia.com/advisories/39298" source="SECUNIA" adv="1">39298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="modxcms">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2.1" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.6.1" edition="p1" />
        <vers num="0.9.6.2" />
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1427" published="2010-04-15" name="CVE-2010-1427" modified="2010-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304" source="CONFIRM" patch="1" adv="1">http://modxcms.com/forums/index.php/topic,47759.msg280304.html#msg280304</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000013.html" source="JVNDB" patch="1">JVNDB-2010-000013</ref>
      <ref url="http://jvn.jp/en/jp/JVN46669729/index.html" source="JVN" patch="1">JVN#46669729</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57635" source="XF">modx-unspecified-xss(57635)</ref>
      <ref url="http://secunia.com/advisories/39298" source="SECUNIA" adv="1">39298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modxcms" name="evolution">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2.1" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.6.1" edition="p1" />
        <vers num="0.9.6.2" />
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1428" published="2010-04-28" name="CVE-2010-1428" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0379.html" source="REDHAT">RHSA-2010:0379</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0378.html" source="REDHAT">RHSA-2010:0378</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0377.html" source="REDHAT">RHSA-2010:0377</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0376.html" source="REDHAT" adv="1">RHSA-2010:0376</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=585899" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=585899</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58148" source="XF">jboss-webconsole-information-disclosure(58148)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0992" source="VUPEN" adv="1">ADV-2010-0992</ref>
      <ref url="http://www.securityfocus.com/bid/39710" source="BID">39710</ref>
      <ref url="http://securitytracker.com/id?1023917" source="SECTRACK">1023917</ref>
      <ref url="http://secunia.com/advisories/39563" source="SECUNIA" adv="1">39563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2" />
        <vers prev="1" num="4.2.0" edition="cp01" />
        <vers prev="1" num="4.2.0" edition="cp02" />
        <vers prev="1" num="4.2.0" edition="cp03" />
        <vers prev="1" num="4.2.0" edition="cp04" />
        <vers prev="1" num="4.2.0" edition="cp05" />
        <vers prev="1" num="4.2.0" edition="cp06" />
        <vers prev="1" num="4.2.0" edition="cp07" />
        <vers prev="1" num="4.2.0" edition="cp08" />
        <vers num="4.3" />
        <vers prev="1" num="4.3.0" edition="cp01" />
        <vers prev="1" num="4.3.0" edition="cp02" />
        <vers prev="1" num="4.3.0" edition="cp03" />
        <vers prev="1" num="4.3.0" edition="cp04" />
        <vers prev="1" num="4.3.0" edition="cp05" />
        <vers prev="1" num="4.3.0" edition="cp06" />
        <vers prev="1" num="4.3.0" edition="cp07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1429" published="2010-04-28" name="CVE-2010-1429" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.  NOTE: this issue exists because of a CVE-2008-3273 regression.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0379.html" source="REDHAT" adv="1">RHSA-2010:0379</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0378.html" source="REDHAT" adv="1">RHSA-2010:0378</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0377.html" source="REDHAT" adv="1">RHSA-2010:0377</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0376.html" source="REDHAT" adv="1">RHSA-2010:0376</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=585900" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=585900</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58149" source="XF">jboss-status-servlet-information-disclosure(58149)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0992" source="VUPEN" adv="1">ADV-2010-0992</ref>
      <ref url="http://www.securityfocus.com/bid/39710" source="BID">39710</ref>
      <ref url="http://securitytracker.com/id?1023918" source="SECTRACK">1023918</ref>
      <ref url="http://secunia.com/advisories/39563" source="SECUNIA" adv="1">39563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2" />
        <vers prev="1" num="4.2.0" edition="cp01" />
        <vers prev="1" num="4.2.0" edition="cp02" />
        <vers prev="1" num="4.2.0" edition="cp03" />
        <vers prev="1" num="4.2.0" edition="cp04" />
        <vers prev="1" num="4.2.0" edition="cp05" />
        <vers prev="1" num="4.2.0" edition="cp06" />
        <vers prev="1" num="4.2.0" edition="cp07" />
        <vers prev="1" num="4.2.0" edition="cp08" />
        <vers num="4.3" />
        <vers prev="1" num="4.3.0" edition="cp01" />
        <vers prev="1" num="4.3.0" edition="cp02" />
        <vers prev="1" num="4.3.0" edition="cp03" />
        <vers prev="1" num="4.3.0" edition="cp04" />
        <vers prev="1" num="4.3.0" edition="cp05" />
        <vers prev="1" num="4.3.0" edition="cp06" />
        <vers prev="1" num="4.3.0" edition="cp07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1431" published="2010-05-04" name="CVE-2010-1431" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cacti.net/downloads/patches/0.8.7e/sql_injection_template_export.patch" source="CONFIRM" patch="1">http://www.cacti.net/downloads/patches/0.8.7e/sql_injection_template_export.patch</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=578909" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=578909</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0635.html" source="REDHAT">RHSA-2010:0635</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0986" source="VUPEN" adv="1">ADV-2010-0986</ref>
      <ref url="http://www.securityfocus.com/bid/39653" source="BID">39653</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:092" source="MANDRIVA">MDVSA-2010:092</ref>
      <ref url="http://www.exploit-db.com/sploits/Bonsai-SQL_Injection_in_Cacti.pdf" source="MISC">http://www.exploit-db.com/sploits/Bonsai-SQL_Injection_in_Cacti.pdf</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2039" source="DEBIAN">DSA-2039</ref>
      <ref url="http://secunia.com/advisories/41041" source="SECUNIA">41041</ref>
      <ref url="http://secunia.com/advisories/39572" source="SECUNIA" adv="1">39572</ref>
      <ref url="http://secunia.com/advisories/39568" source="SECUNIA" adv="1">39568</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Apr/272" source="FULLDISC">20100421 Bonsai Information Security - SQL Injection in Cacti &lt;= 0.8.7e</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cacti" name="cacti">
        <vers num="0.5" edition="-" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6f" />
        <vers num="0.8.6g" />
        <vers num="0.8.6h" />
        <vers num="0.8.6i" />
        <vers num="0.8.6j" />
        <vers num="0.8.6k" />
        <vers num="0.8.7" />
        <vers num="0.8.7a" />
        <vers num="0.8.7b" />
        <vers num="0.8.7c" />
        <vers num="0.8.7d" />
        <vers prev="1" num="0.8.7e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1436" published="2010-05-21" name="CVE-2010-1436" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">gfs2 in the Linux kernel 2.6.18, and possibly other versions, does not properly handle when the gfs2_quota struct occupies two separate pages, which allows local users to cause a denial of service (kernel panic) via certain manipulations that cause an out-of-bounds write, as demonstrated by writing from an ext3 file system to a gfs2 file system.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=586006" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=586006</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58839" source="XF">kernel-gfs2quota-dos(58839)</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/28/1" source="MLIST">[oss-security] 20100427 Re: CVE request - gfs2 kernel issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/27/1" source="MLIST">[oss-security] 20100427 CVE request - gfs2 kernel issue</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10652" source="OVAL">oval:org.mitre.oval:def:10652</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1437" published="2010-05-07" name="CVE-2010-1437" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://patchwork.kernel.org/patch/94664/" source="CONFIRM" patch="1">https://patchwork.kernel.org/patch/94664/</ref>
      <ref url="https://patchwork.kernel.org/patch/94038/" source="CONFIRM">https://patchwork.kernel.org/patch/94038/</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=585094" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=585094</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58254" source="XF">kernel-findkeyringbyname-dos(58254)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/39719" source="BID">39719</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0474.html" source="REDHAT">RHSA-2010:0474</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/28/2" source="MLIST">[oss-security] 20100427 Re: CVE request - kernel: find_keyring_by_name() can gain the freed keyring</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/27/2" source="MLIST">[oss-security] 20100427 CVE request - kernel: find_keyring_by_name() can gain the freed keyring</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://secunia.com/advisories/40218" source="SECUNIA">40218</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9715" source="OVAL">oval:org.mitre.oval:def:9715</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=127292492727029&amp;w=2" source="MLIST">[linux-kernel] 20100503 Re: [PATCH 2/7] KEYS: find_keyring_by_name() can gain access to a freed keyring</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=127274294622730&amp;w=2" source="MLIST">[linux-kernel] 20100430 [PATCH 2/7] KEYS: find_keyring_by_name() can gain access to a freed keyring</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=127192182917857&amp;w=2" source="MLIST">[linux-kernel] 20100422 [PATCH 0/1][BUG][IMPORTANT] KEYRINGS: find_keyring_by_name() can gain the freed keyring</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33" edition="rc7" />
        <vers num="2.6.33" edition="rc8" />
        <vers num="2.6.33.1" />
        <vers prev="1" num="2.6.34" edition="rc1" />
        <vers prev="1" num="2.6.34" edition="rc2" />
        <vers prev="1" num="2.6.34" edition="rc3" />
        <vers prev="1" num="2.6.34" edition="rc4" />
        <vers prev="1" num="2.6.34" edition="rc5" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1438" published="2010-05-06" name="CVE-2010-1438" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39760" source="BID">39760</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/28/3" source="MLIST">[oss-security] 20100427 Re: wafp insecure temporary directory</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/27/6" source="MLIST">[oss-security] 20100427 wafp insecure temporary directory</ref>
      <ref url="http://code.google.com/p/webapplicationfingerprinter/issues/detail?id=8" source="MISC">http://code.google.com/p/webapplicationfingerprinter/issues/detail?id=8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mytty" name="webapplication_finger_printer">
        <vers num="0.01-26c3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1439" published="2010-06-07" name="CVE-2010-1439" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=585386" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=585386</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59114" source="XF">redhat-clienttools-loginauth-security-bypass(59114)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1311" source="VUPEN" adv="1">ADV-2010-1311</ref>
      <ref url="http://www.securityfocus.com/bid/40492" source="BID">40492</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0449.html" source="REDHAT">RHSA-2010:0449</ref>
      <ref url="http://www.osvdb.org/65063" source="OSVDB">65063</ref>
      <ref url="http://securitytracker.com/id?1024049" source="SECTRACK">1024049</ref>
      <ref url="http://secunia.com/advisories/39996" source="SECUNIA" adv="1">39996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9232" source="OVAL">oval:org.mitre.oval:def:9232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="yum-rhn-plugin">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1440" published="2010-05-07" name="CVE-2010-1440" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=586819" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=586819</ref>
      <ref url="http://www.ubuntu.com/usn/USN-937-1" source="UBUNTU">USN-937-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10068" source="OVAL">oval:org.mitre.oval:def:10068</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041573.html" source="FEDORA">FEDORA-2010-8273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tug" name="tetex">
        <vers num="" />
      </prod>
      <prod vendor="tug" name="tex_live">
        <vers num="1996" />
        <vers num="1998" />
        <vers num="1999" />
        <vers num="2000" />
        <vers num="2001" />
        <vers num="2002" />
        <vers num="2003" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2007" />
        <vers num="2008" />
        <vers prev="1" num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1446" published="2010-05-21" name="CVE-2010-1446" modified="2010-08-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">arch/powerpc/mm/fsl_booke_mmu.c in KGDB in the Linux kernel 2.6.30 and other versions before 2.6.33, when running on PowerPC, does not properly perform a security check for access to a kernel page, which allows local users to overwrite arbitrary kernel memory, related to Fsl booke.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lkml.org/lkml/2010/5/10/458" source="MLIST" patch="1">[linux-kernel] 20100510 [071/117] kgdb: dont needlessly skip PAGE_USER test for Fsl booke</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58840" source="XF">kernel-kgdb-memory-overwrite(58840)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/30/1" source="MLIST">[oss-security] 20100430 Re: CVE request - Linux Kernel KGDB/ppc issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/29/9" source="MLIST">[oss-security] 20100429 Re: CVE request - Linux Kernel KGDB/ppc issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/29/3" source="MLIST">[oss-security] 20100429 CVE request - Linux Kernel KGDB/ppc issue</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.12" />
        <vers num="2.6.32.13" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1447" published="2010-05-19" name="CVE-2010-1447" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access restrictions, and inject and execute arbitrary code, via vectors involving subroutine references and delayed execution.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1167" source="VUPEN" patch="1" adv="1">ADV-2010-1167</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=588269" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=588269</ref>
      <ref url="https://bugs.launchpad.net/bugs/cve/2010-1447" source="CONFIRM">https://bugs.launchpad.net/bugs/cve/2010-1447</ref>
      <ref url="http://www.securitytracker.com/id?1023988" source="SECTRACK">1023988</ref>
      <ref url="http://www.securityfocus.com/bid/40305" source="BID">40305</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0458.html" source="REDHAT">RHSA-2010:0458</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0457.html" source="REDHAT">RHSA-2010:0457</ref>
      <ref url="http://www.postgresql.org/about/news.1203" source="CONFIRM">http://www.postgresql.org/about/news.1203</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/20/5" source="MLIST">[oss-security] 20100520 CVE-2010-1974 reject request (dupe of CVE-2010-1168) and CVE-2010-1447 description modification request</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:116" source="MANDRIVA">MDVSA-2010:116</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:115" source="MANDRIVA">MDVSA-2010:115</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2267" source="DEBIAN">DSA-2267</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1447" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1447</ref>
      <ref url="http://secunia.com/advisories/40052" source="SECUNIA">40052</ref>
      <ref url="http://secunia.com/advisories/40049" source="SECUNIA">40049</ref>
      <ref url="http://secunia.com/advisories/39845" source="SECUNIA" adv="1">39845</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7320" source="OVAL">oval:org.mitre.oval:def:7320</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11530" source="OVAL">oval:org.mitre.oval:def:11530</ref>
      <ref url="http://osvdb.org/64756" source="OSVDB">64756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.12" />
        <vers num="7.4.13" />
        <vers num="7.4.14" />
        <vers num="7.4.15" />
        <vers num="7.4.16" />
        <vers num="7.4.17" />
        <vers num="7.4.18" />
        <vers num="7.4.19" />
        <vers num="7.4.2" />
        <vers num="7.4.20" />
        <vers num="7.4.21" />
        <vers num="7.4.22" />
        <vers num="7.4.23" />
        <vers num="7.4.24" />
        <vers num="7.4.25" />
        <vers num="7.4.26" />
        <vers num="7.4.27" />
        <vers num="7.4.28" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.11" />
        <vers num="8.0.12" />
        <vers num="8.0.13" />
        <vers num="8.0.14" />
        <vers num="8.0.15" />
        <vers num="8.0.16" />
        <vers num="8.0.17" />
        <vers num="8.0.18" />
        <vers num="8.0.19" />
        <vers num="8.0.2" />
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.0.23" />
        <vers num="8.0.24" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.10" />
        <vers num="8.1.11" />
        <vers num="8.1.12" />
        <vers num="8.1.13" />
        <vers num="8.1.14" />
        <vers num="8.1.15" />
        <vers num="8.1.16" />
        <vers num="8.1.17" />
        <vers num="8.1.18" />
        <vers num="8.1.19" />
        <vers num="8.1.2" />
        <vers num="8.1.20" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8" />
        <vers num="8.1.9" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.10" />
        <vers num="8.2.11" />
        <vers num="8.2.12" />
        <vers num="8.2.13" />
        <vers num="8.2.14" />
        <vers num="8.2.15" />
        <vers num="8.2.16" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.2.8" />
        <vers num="8.2.9" />
        <vers num="8.3" />
        <vers num="8.3.1" />
        <vers num="8.3.10" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.3.7" />
        <vers num="8.3.8" />
        <vers num="8.3.9" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.2" />
        <vers num="8.4.3" />
        <vers num="9.0.0" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1448" published="2010-06-24" name="CVE-2010-1448" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in lib/LXR/Common.pm in LXR Cross Referencer before 0.9.8 allows remote attackers to inject arbitrary web script or HTML via vectors related to a string in the search page's TITLE element, a different vulnerability than CVE-2009-4497 and CVE-2010-1625.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.8/lxr-0.9.8.tgz/download" source="CONFIRM" patch="1">http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.8/lxr-0.9.8.tgz/download</ref>
      <ref url="http://lxr.cvs.sourceforge.net/viewvc/lxr/lxr/lib/LXR/Common.pm?r1=1.63&amp;r2=1.64" source="CONFIRM" patch="1">http://lxr.cvs.sourceforge.net/viewvc/lxr/lxr/lib/LXR/Common.pm?r1=1.63&amp;r2=1.64</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58294" source="XF">lxr-title-xss(58294)</ref>
      <ref url="http://www.securityfocus.com/bid/39865" source="BID">39865</ref>
      <ref url="http://www.osvdb.org/64216" source="OSVDB">64216</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/14/3" source="MLIST">[oss-security] 20100514 Re: CVE request: lxr</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/06/2" source="MLIST">[oss-security] 20100506 Re: CVE request: lxr</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/03/7" source="MLIST">[oss-security] 20100503 Re: CVE request: lxr</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/03/1" source="MLIST">[oss-security] 20100503 CVE request: lxr</ref>
      <ref url="http://secunia.com/advisories/39686" source="SECUNIA">39686</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127316953819027&amp;w=2" source="MLIST">[oss-security] 20100506 Re: CVE request: lxr</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127291817517567&amp;w=2" source="MLIST">[oss-security] 20100503 Re: CVE request: lxr</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127289957223005&amp;w=2" source="MLIST">[oss-security] 20100503 Re: CVE request: lxr</ref>
      <ref url="http://lxr.cvs.sourceforge.net/viewvc/lxr/lxr/lib/LXR/Common.pm?view=log#rev1.64" source="CONFIRM">http://lxr.cvs.sourceforge.net/viewvc/lxr/lxr/lib/LXR/Common.pm?view=log#rev1.64</ref>
    </refs>
    <vuln_soft>
      <prod vendor="malcom_box" name="lxr_cross_referencer">
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers prev="1" num="0.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1449" published="2010-05-27" name="CVE-2010-1449" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-3143.12.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=541698" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=541698</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0413" source="VUPEN">ADV-2011-0413</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0122" source="VUPEN">ADV-2011-0122</ref>
      <ref url="http://www.securityfocus.com/bid/40363" source="BID">40363</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0260.html" source="REDHAT">RHSA-2011:0260</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0027.html" source="REDHAT">RHSA-2011:0027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:215" source="MANDRIVA">MDVSA-2010:215</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/43364" source="SECUNIA">43364</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42888" source="SECUNIA">42888</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://bugs.python.org/issue8678" source="CONFIRM">http://bugs.python.org/issue8678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python" name="python">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1450" published="2010-05-27" name="CVE-2010-1450" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=541698" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=541698</ref>
      <ref url="http://bugs.python.org/issue8678" source="CONFIRM" patch="1">http://bugs.python.org/issue8678</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0413" source="VUPEN">ADV-2011-0413</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0122" source="VUPEN">ADV-2011-0122</ref>
      <ref url="http://www.securityfocus.com/bid/40365" source="BID">40365</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0260.html" source="REDHAT">RHSA-2011:0260</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0027.html" source="REDHAT">RHSA-2011:0027</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:215" source="MANDRIVA">MDVSA-2010:215</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://secunia.com/advisories/43364" source="SECUNIA">43364</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42888" source="SECUNIA">42888</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python" name="python">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1451" published="2010-05-07" name="CVE-2010-1451" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=linux-sparc&amp;m=126662159602378&amp;w=2" source="MLIST" patch="1">[linux-sparc] 20100219 Re: Execution possible in non-executable mappings in recent 2.6 kernels</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/05/2" source="MLIST">[oss-security] 20100505 Re: CVE Request [was Re: kernel: execution possible in non-executable mappings in recent 2.6 kernels (SPARC only)]</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/02/24/1" source="MLIST">[oss-security] 20100224 kernel: execution possible in non-executable mappings in recent 2.6 kernels (SPARC only)</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2053" source="DEBIAN">DSA-2053</ref>
      <ref url="http://secunia.com/advisories/39830" source="SECUNIA">39830</ref>
      <ref url="http://marc.info/?l=linux-sparc&amp;m=126662196902830&amp;w=2" source="MLIST">[linux-sparc] 20100219 Execution possible in non-executable mappings in recent 2.6 kernels</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers prev="1" num="2.6.32.12" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33.1" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1452" published="2010-07-28" name="CVE-2010-1452" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://httpd.apache.org/security/vulnerabilities_22.html

'A flaw was found in the handling of requests by mod_cache and mod_dav. A malicious remote attacker could send a carefully crafted request and cause a httpd child process to crash. This crash would only be a denial of service if using the worker MPM. This issue is further mitigated as mod_dav is only affected by requests that are most likely to be authenticated, and mod_cache is only affected if the uncommon "CacheIgnoreURLSessionIdentifiers" directive, introduced in version 2.2.14, is used.'</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=apache-announce&amp;m=128009718610929&amp;w=2" source="MLIST" patch="1" adv="1">[apache-announce] 20100725 [ANNOUNCEMENT] Apache HTTP Server 2.2.16 Released</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=49246" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=49246</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0291" source="VUPEN">ADV-2011-0291</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3064" source="VUPEN">ADV-2010-3064</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2218" source="VUPEN">ADV-2010-2218</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0897.html" source="REDHAT">RHSA-2011:0897</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0896.html" source="REDHAT">RHSA-2011:0896</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0659.html" source="REDHAT">RHSA-2010:0659</ref>
      <ref url="http://ubuntu.com/usn/usn-1021-1" source="UBUNTU">USN-1021-1</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.467395" source="SLACKWARE">SSA:2010-240-02</ref>
      <ref url="http://secunia.com/advisories/42367" source="SECUNIA">42367</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12341" source="OVAL">oval:org.mitre.oval:def:12341</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11683" source="OVAL">oval:org.mitre.oval:def:11683</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html" source="SUSE">SUSE-SU-2011:1216</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html" source="SUSE">SUSE-SU-2011:1000</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_1452_mod_dav" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_1452_mod_dav</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1453" published="2010-05-07" name="CVE-2010-1453" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1079" source="VUPEN" patch="1" adv="1">ADV-2010-1079</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/05/4" source="MLIST">[oss-security] 20100505 Re: CVE Request - Piwik 0.5.5 - XSS vulnerability</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/05/3" source="MLIST">[oss-security] 20100505 CVE Request - Piwik 0.5.5 - XSS vulnerability</ref>
      <ref url="http://secunia.com/advisories/39666" source="SECUNIA" adv="1">39666</ref>
      <ref url="http://piwik.org/blog/2010/04/piwik-0-6-security-advisory/" source="CONFIRM" adv="1">http://piwik.org/blog/2010/04/piwik-0-6-security-advisory/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="piwik" name="piwik">
        <vers num="0.1.10" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2.1" />
        <vers num="0.2.10" />
        <vers num="0.2.11" />
        <vers num="0.2.12" />
        <vers num="0.2.13" />
        <vers num="0.2.14" />
        <vers num="0.2.16" />
        <vers num="0.2.17" />
        <vers num="0.2.18" />
        <vers num="0.2.19" />
        <vers num="0.2.2" />
        <vers num="0.2.20" />
        <vers num="0.2.22" />
        <vers num="0.2.23" />
        <vers num="0.2.24" />
        <vers num="0.2.25" />
        <vers num="0.2.26" />
        <vers num="0.2.27" />
        <vers num="0.2.28" />
        <vers num="0.2.29" />
        <vers num="0.2.3" />
        <vers num="0.2.30" />
        <vers num="0.2.31" />
        <vers num="0.2.32" />
        <vers num="0.2.33" />
        <vers num="0.2.34" />
        <vers num="0.2.35" />
        <vers num="0.2.36" />
        <vers num="0.2.37" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
        <vers num="0.4" edition="rc1" />
        <vers num="0.4" edition="rc2" />
        <vers num="0.4" edition="rc3" />
        <vers num="0.4.1" edition="rc1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" edition="rc1" />
        <vers num="0.5.5" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1454" published="2010-05-19" name="CVE-2010-1454" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which allows remote attackers to obtain JMX interface access via a blank password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58684" source="XF">tcserver-listener-security-bypass(58684)</ref>
      <ref url="http://www.springsource.com/security/cve-2010-1454" source="CONFIRM" adv="1">http://www.springsource.com/security/cve-2010-1454</ref>
      <ref url="http://www.securityfocus.com/bid/40205" source="BID">40205</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511307/100/0/threaded" source="BUGTRAQ">20100517 CVE-2010-1454: SpringSource tc Server unauthenticated remote access to JMX interface</ref>
      <ref url="http://secunia.com/advisories/39778" source="SECUNIA" adv="1">39778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="tc_server">
        <vers num="6.0.19" />
        <vers num="6.0.19.a" />
        <vers num="6.0.20" />
        <vers num="6.0.20.a" />
        <vers num="6.0.20.b" />
        <vers num="6.0.20.c" />
        <vers num="6.0.25.a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1455" published="2010-05-12" name="CVE-2010-1455" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1081" source="VUPEN" patch="1" adv="1">ADV-2010-1081</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4646" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4646</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4644" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4644</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58362" source="XF">wireshark-docsis-dos(58362)</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2010-04.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2010-04.html</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2010-03.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2010-03.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0076" source="VUPEN">ADV-2011-0076</ref>
      <ref url="http://www.securityfocus.com/bid/39950" source="BID">39950</ref>
      <ref url="http://www.osvdb.org/64363" source="OSVDB">64363</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/07/7" source="MLIST">[oss-security] 20100507 Re: CVE Assignment (wireshark)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:099" source="MANDRIVA">MDVSA-2010:099</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42877" source="SECUNIA">42877</ref>
      <ref url="http://secunia.com/advisories/39661" source="SECUNIA" adv="1">39661</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7331" source="OVAL">oval:org.mitre.oval:def:7331</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html" source="SUSE">SUSE-SR:2011:001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ethereal_group" name="ethereal">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.99.0" />
      </prod>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.9.6" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1456" reject="1" published="2010-05-19" name="CVE-2010-1456" modified="2010-05-19">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1455.  Reason: This candidate is a duplicate of CVE-2010-1455.  Notes: All CVE users should reference CVE-2010-1455 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1457" published="2010-05-12" name="CVE-2010-1457" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 allows local users to read arbitrary files via a (1) -c or (2) -a option, which prints file contents in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ftpmain.gnustep.org/pub/gnustep/core/gnustep-base-1.20.0.tar.gz" source="CONFIRM" patch="1">http://ftpmain.gnustep.org/pub/gnustep/core/gnustep-base-1.20.0.tar.gz</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/gnustep-base/+bug/573108" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/gnustep-base/+bug/573108</ref>
      <ref url="http://www.securityfocus.com/bid/40005" source="BID">40005</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/07/6" source="MLIST">[oss-security] 20100507 CVE Assignment (gnustep)</ref>
      <ref url="http://thread.gmane.org/gmane.comp.lib.gnustep.bugs/12336" source="CONFIRM">http://thread.gmane.org/gmane.comp.lib.gnustep.bugs/12336</ref>
      <ref url="http://secunia.com/advisories/39746" source="SECUNIA" adv="1">39746</ref>
      <ref url="http://savannah.gnu.org/bugs/?29755" source="CONFIRM">http://savannah.gnu.org/bugs/?29755</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnustep" name="gnustep_base">
        <vers num="1.11.2" />
        <vers num="1.12.0" />
        <vers num="1.13.0" />
        <vers num="1.14.0" />
        <vers num="1.15.0" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.4" />
        <vers num="1.17.0" />
        <vers num="1.18.0" />
        <vers num="1.19.0" />
        <vers num="1.19.1" />
        <vers num="1.19.2" />
        <vers prev="1" num="1.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1458" published="2010-04-20" name="CVE-2010-1458" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitrary code via a long filename in a ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57912" source="XF">tzu-zip-bo(57912)</ref>
      <ref url="http://www.securityfocus.com/bid/39565" source="BID">39565</ref>
      <ref url="http://www.osvdb.org/63899" source="OSVDB">63899</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-026-tweakfs-zip-utility-version-1-0-stack-bof/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-026-tweakfs-zip-utility-version-1-0-stack-bof/</ref>
      <ref url="http://www.corelan.be:8800/advisories.php?id=CORELAN-10-026" source="MISC">http://www.corelan.be:8800/advisories.php?id=CORELAN-10-026</ref>
      <ref url="http://secunia.com/advisories/39519" source="SECUNIA" adv="1">39519</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0242.html" source="FULLDISC">20100419 [CORELAN-10-026] TweakFS Zip Stack BOF</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tweakfs" name="tweakfs_zip_utility">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1459" published="2010-05-27" name="CVE-2010-1459" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40351" source="BID">40351</ref>
      <ref url="http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting" source="CONFIRM" adv="1">http://www.mono-project.com/Vulnerabilities#ASP.NET_View_State_Cross-Site_Scripting</ref>
      <ref url="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx" source="MISC">http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/04/29/asp-net-cross-site-scripting-followup-mono.aspx</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mono" name="mono">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10.1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.12.1" />
        <vers num="1.1.13" />
        <vers num="1.1.13.2" />
        <vers num="1.1.13.4" />
        <vers num="1.1.13.5" />
        <vers num="1.1.13.6" />
        <vers num="1.1.13.7" />
        <vers num="1.1.13.8" />
        <vers num="1.1.13.8.1" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.16.1" />
        <vers num="1.1.17" />
        <vers num="1.1.17.1" />
        <vers num="1.1.17.2" />
        <vers num="1.1.18" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.8.1" />
        <vers num="1.1.8.3" />
        <vers num="1.1.9" />
        <vers num="1.1.9.1" />
        <vers num="1.1.9.2" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.2.1" />
        <vers num="1.2.3" />
        <vers num="1.2.3.1" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.5.1" />
        <vers num="1.2.5.2" />
        <vers num="1.2.6" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.2" />
        <vers num="2.4" />
        <vers num="2.4.2" />
        <vers num="2.4.2.1" />
        <vers num="2.4.2.2" />
        <vers num="2.4.2.3" />
        <vers num="2.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1460" published="2010-04-16" name="CVE-2010-1460" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-947.ibm.com/systems/support/supportsite.wss/docdisplay?lndocid=MIGR-5083945&amp;brandind=5000020" source="CONFIRM" patch="1">http://www-947.ibm.com/systems/support/supportsite.wss/docdisplay?lndocid=MIGR-5083945&amp;brandind=5000020</ref>
      <ref url="http://www.securityfocus.com/bid/39499" source="BID">39499</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510744/100/0/threaded" source="BUGTRAQ">20100415 [DSECRG-09-049] IBM BladeCenter Management Module - DoS vulnerability</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=149" source="MISC">http://dsecrg.com/pages/vul/show.php?id=149</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="advanced_management_module">
        <vers num="1.00" />
        <vers num="1.01" />
        <vers num="1.20" edition="f" />
        <vers num="1.25" edition="e" />
        <vers num="1.25" edition="i" />
        <vers num="1.26" edition="b" />
        <vers num="1.26" edition="e" />
        <vers num="1.26" edition="h" />
        <vers num="1.26" edition="i" />
        <vers num="1.26" edition="k" />
        <vers num="1.28" edition="g" />
        <vers num="1.32" edition="d" />
        <vers num="1.34" edition="b" />
        <vers num="1.34" edition="e" />
        <vers num="1.36" edition="d" />
        <vers num="1.36" edition="g" />
        <vers num="1.36" edition="h" />
        <vers num="1.36" edition="k" />
        <vers num="1.42" edition="d" />
        <vers num="1.42" edition="f" />
        <vers num="1.42" edition="i" />
        <vers num="1.42" edition="n" />
        <vers num="1.42" edition="o" />
        <vers num="1.42" edition="t" />
        <vers num="2.46" edition="c" />
        <vers num="2.46" edition="j" />
        <vers num="2.48" edition="c" />
        <vers num="2.48" edition="d" />
        <vers num="2.48" edition="g" />
        <vers num="2.48" edition="l" />
        <vers num="2.48" edition="n" />
        <vers prev="1" num="2.50" edition="c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1461" published="2010-04-16" name="CVE-2010-1461" modified="2010-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39504" source="BID">39504</ref>
      <ref url="http://www.exploit-db.com/exploits/12232" source="EXPLOIT-DB">12232</ref>
      <ref url="http://secunia.com/advisories/39469" source="SECUNIA" adv="1">39469</ref>
      <ref url="http://osvdb.org/63800" source="OSVDB">63800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gogoritas" name="com_photobattle">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1462" published="2010-04-16" name="CVE-2010-1462" modified="2010-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in WebAsyst Shop-Script FREE has unknown impact and attack vectors via the sub parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/research-web.php" source="MISC" adv="1">http://www.vupen.com/english/research-web.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0882" source="VUPEN" adv="1">ADV-2010-0882</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510741/100/0/threaded" source="BUGTRAQ">20100414 VUPEN Web Security Research - WebAsyst Shop-Script Multiple Input Validation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webasyst_llc" name="shop-script">
        <vers num="" edition=":free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1463" published="2010-04-16" name="CVE-2010-1463" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in WebAsyst Shop-Script FREE allow attackers to execute arbitrary SQL commands via the (1) add2cart, (2) c_id, (3) categoryID, (4) list_price, (5) name, (6) new_offer, (7) price, (8) product_code, (9) productID, (10) rating, and (11) save_product parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/research-web.php" source="MISC" adv="1">http://www.vupen.com/english/research-web.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0882" source="VUPEN" adv="1">ADV-2010-0882</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510741/100/0/threaded" source="BUGTRAQ">20100414 VUPEN Web Security Research - WebAsyst Shop-Script Multiple Input Validation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webasyst_llc" name="shop-script">
        <vers num="" edition=":free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1464" published="2010-04-16" name="CVE-2010-1464" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in WebAsyst Shop-Script FREE allow remote attackers to inject arbitrary web script or HTML via the (1) currency_id_left, (2) currency_id_right, (3) darkcolor, (4) lightcolor, (5) middlecolor, and (6) w parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/research-web.php" source="MISC" adv="1">http://www.vupen.com/english/research-web.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0882" source="VUPEN" adv="1">ADV-2010-0882</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510741/100/0/threaded" source="BUGTRAQ">20100414 VUPEN Web Security Research - WebAsyst Shop-Script Multiple Input Validation Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webasyst" name="shop-script">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1465" published="2010-04-16" name="CVE-2010-1465" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57778" source="XF">trellian-pasv-bo(57778)</ref>
      <ref url="http://www.exploit-db.com/exploits/12152" source="EXPLOIT-DB">12152</ref>
      <ref url="http://secunia.com/advisories/39370" source="SECUNIA" adv="1">39370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trellian" name="ftp">
        <vers num="3.01" />
        <vers num="3.1.3.1789" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1466" published="2010-04-16" name="CVE-2010-1466" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57816" source="XF">vaccin-soustab-file-include(57816)</ref>
      <ref url="http://www.securityfocus.com/bid/39412" source="BID">39412</ref>
      <ref url="http://www.exploit-db.com/exploits/12193" source="EXPLOIT-DB">12193</ref>
      <ref url="http://secunia.com/advisories/39400" source="SECUNIA" adv="1">39400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francois_raynaud" name="openurgence_vaccin">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1467" published="2010-04-16" name="CVE-2010-1467" modified="2010-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) collectivite.class.php, (2) injection.class.php, (3) utilisateur.class.php, (4) droit.class.php, (5) laboratoire.class.php, (6) vaccin.class.php, (7) effetsecondaire.class.php, (8) medecin.class.php, (9) individu.class.php, and (10) profil.class.php in gen/obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57815" source="XF">vaccin-pathom-file-include(57815)</ref>
      <ref url="http://www.securityfocus.com/bid/39412" source="BID">39412</ref>
      <ref url="http://www.exploit-db.com/exploits/12193" source="EXPLOIT-DB">12193</ref>
      <ref url="http://secunia.com/advisories/39400" source="SECUNIA" adv="1">39400</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francois_raynaud" name="openurgence_vaccin">
        <vers num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1468" published="2010-04-19" name="CVE-2010-1468" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Multi-Venue Restaurant Menu Manager (aka MVRMM or com_mv_restaurantmenumanager) component 1.5.2 Stable Update 3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the mid parameter in a menu_display action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xenuser.org/documents/security/joomla_com_MVRMM_sql.txt" source="MISC">http://www.xenuser.org/documents/security/joomla_com_MVRMM_sql.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39382" source="BID">39382</ref>
      <ref url="http://www.exploit-db.com/exploits/12159" source="EXPLOIT-DB">12159</ref>
      <ref url="http://secunia.com/advisories/39217" source="SECUNIA" adv="1">39217</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlamvrmm-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlamvrmm-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="focusdev" name="com_mv_restaurantmenumanager">
        <vers prev="1" num="1.5.2" edition="stable_update_3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1469" published="2010-04-19" name="CVE-2010-1469" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39383" source="BID">39383</ref>
      <ref url="http://www.exploit-db.com/exploits/12146" source="EXPLOIT-DB">12146</ref>
      <ref url="http://secunia.com/advisories/39282" source="SECUNIA" adv="1">39282</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajprojectmanager-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajprojectmanager-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ternaria" name="com_jprojectmanager">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1470" published="2010-04-19" name="CVE-2010-1470" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0858" source="VUPEN" adv="1">ADV-2010-0858</ref>
      <ref url="http://www.exploit-db.com/exploits/12166" source="EXPLOIT-DB">12166</ref>
      <ref url="http://secunia.com/advisories/39405" source="SECUNIA" adv="1">39405</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlawebtv-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlawebtv-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev.pucit.edu.pk" name="com_webtv">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1471" published="2010-04-19" name="CVE-2010-1471" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0862" source="VUPEN" adv="1">ADV-2010-0862</ref>
      <ref url="http://www.exploit-db.com/exploits/12170" source="EXPLOIT-DB">12170</ref>
      <ref url="http://secunia.com/advisories/39412" source="SECUNIA" adv="1">39412</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaaddressbook-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaaddressbook-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="b-elektro" name="com_addressbook">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1472" published="2010-04-19" name="CVE-2010-1472" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0859" source="VUPEN" adv="1">ADV-2010-0859</ref>
      <ref url="http://www.exploit-db.com/exploits/12167" source="EXPLOIT-DB">12167</ref>
      <ref url="http://secunia.com/advisories/39406" source="SECUNIA" adv="1">39406</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlahoroscope-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlahoroscope-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kazulah" name="com_horoscope">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1473" published="2010-04-19" name="CVE-2010-1473" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/12171" source="EXPLOIT-DB">12171</ref>
      <ref url="http://secunia.com/advisories/39410" source="SECUNIA" adv="1">39410</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaeasyadbanner-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaeasyadbanner-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="johnmccollum" name="com_advertising">
        <vers num="0.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1474" published="2010-04-19" name="CVE-2010-1474" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57662" source="XF">comsweetykeeper-controller-file-include(57662)</ref>
      <ref url="http://www.securityfocus.com/bid/39399" source="BID">39399</ref>
      <ref url="http://www.exploit-db.com/exploits/12182" source="EXPLOIT-DB">12182</ref>
      <ref url="http://secunia.com/advisories/39388" source="SECUNIA" adv="1">39388</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlasweetykeeper-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlasweetykeeper-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="supachai_teasakul" name="com_sweetykeeper">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1475" published="2010-04-19" name="CVE-2010-1475" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Preventive &amp; Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57652" source="XF">compreventive-controller-file-include(57652)</ref>
      <ref url="http://www.securityfocus.com/bid/39387" source="BID">39387</ref>
      <ref url="http://www.exploit-db.com/exploits/12147" source="EXPLOIT-DB">12147</ref>
      <ref url="http://secunia.com/advisories/39285" source="SECUNIA" adv="1">39285</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlapr-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlapr-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ternaria" name="com_preventive">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1476" published="2010-04-19" name="CVE-2010-1476" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39393" source="BID">39393</ref>
      <ref url="http://www.exploit-db.com/exploits/12150" source="EXPLOIT-DB">12150</ref>
      <ref url="http://www.alphaplug.com/" source="CONFIRM" adv="1">http://www.alphaplug.com/</ref>
      <ref url="http://secunia.com/advisories/39250" source="SECUNIA" adv="1">39250</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaalphauserpoints-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaalphauserpoints-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alphaplug" name="com_alphauserpoints">
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1477" published="2010-04-19" name="CVE-2010-1477" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://joomlacode.org/gf/project/sermon_speaker/news/?action=NewsThreadView&amp;id=2549" source="CONFIRM" patch="1">http://joomlacode.org/gf/project/sermon_speaker/news/?action=NewsThreadView&amp;id=2549</ref>
      <ref url="http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;forum_id=7897&amp;_forum_action=ForumMessageBrowse&amp;thread_id=15219" source="CONFIRM" patch="1">http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;forum_id=7897&amp;_forum_action=ForumMessageBrowse&amp;thread_id=15219</ref>
      <ref url="http://www.securityfocus.com/bid/39410" source="BID">39410</ref>
      <ref url="http://www.exploit-db.com/exploits/12184" source="EXPLOIT-DB">12184</ref>
      <ref url="http://secunia.com/advisories/39385" source="SECUNIA" adv="1">39385</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlasermonspeaker-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlasermonspeaker-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_hess" name="com_sermonspeaker">
        <vers num="2.9" />
        <vers prev="1" num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1478" published="2010-04-19" name="CVE-2010-1478" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39390" source="BID">39390</ref>
      <ref url="http://www.exploit-db.com/exploits/12145" source="EXPLOIT-DB">12145</ref>
      <ref url="http://secunia.com/advisories/39262" source="SECUNIA" adv="1">39262</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajfeedback-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajfeedback-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ternaria" name="com_jfeedback">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1479" published="2010-04-19" name="CVE-2010-1479" modified="2010-06-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rockettheme.com/extensions-updates/673-rokmodule-security-update-released" source="CONFIRM" patch="1" adv="1">http://www.rockettheme.com/extensions-updates/673-rokmodule-security-update-released</ref>
      <ref url="http://www.securityfocus.com/bid/39378" source="BID">39378</ref>
      <ref url="http://www.rockettheme.com/extensions-downloads/free/rokmodule/1040-rokmodule-component/download" source="CONFIRM">http://www.rockettheme.com/extensions-downloads/free/rokmodule/1040-rokmodule-component/download</ref>
      <ref url="http://www.exploit-db.com/exploits/12148" source="EXPLOIT-DB">12148</ref>
      <ref url="http://secunia.com/advisories/39255" source="SECUNIA" adv="1">39255</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlarokmodule-bsql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlarokmodule-bsql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockettheme" name="com_rokmodule">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1480" published="2010-04-19" name="CVE-2010-1480" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rockettheme.com/extensions-updates/673-rokmodule-security-update-released" source="MISC" adv="1">http://www.rockettheme.com/extensions-updates/673-rokmodule-security-update-released</ref>
      <ref url="http://www.rockettheme.com/extensions-downloads/free/rokmodule/1040-rokmodule-component/download" source="MISC" adv="1">http://www.rockettheme.com/extensions-downloads/free/rokmodule/1040-rokmodule-component/download</ref>
      <ref url="http://secunia.com/advisories/39255" source="SECUNIA" adv="1">39255</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockettheme" name="com_rokmodule">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1481" published="2010-05-12" name="CVE-2010-1481" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39994" source="BID">39994</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511177/100/0/threaded" source="BUGTRAQ">20100507 pmwiki: persistent cross site scripting (XSS), CVE-2010-1481</ref>
      <ref url="http://secunia.com/advisories/39698" source="SECUNIA" adv="1">39698</ref>
      <ref url="http://int21.de/cve/CVE-2010-1481-pmwiki-xss.html" source="MISC">http://int21.de/cve/CVE-2010-1481-pmwiki-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmwiki" name="pmwiki">
        <vers num="2.2.15" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1482" published="2010-05-12" name="CVE-2010-1482" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/editprefs.php in the backend in CMS Made Simple (CMSMS) before 1.7.1 might allow remote attackers to inject arbitrary web script or HTML via the date_format_string parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39997" source="BID" patch="1">39997</ref>
      <ref url="http://www.securityfocus.com/archive/1/511178" source="BUGTRAQ">20100507 CMS Made Simple: backend cross site scripting (XSS), CVE-2010-1482</ref>
      <ref url="http://int21.de/cve/CVE-2010-1482-cmsmadesimple-xss-backend.html" source="MISC">http://int21.de/cve/CVE-2010-1482-cmsmadesimple-xss-backend.html</ref>
      <ref url="http://blog.cmsmadesimple.org/2010/05/01/announcing-cms-made-simple-1-7-1-escade/" source="CONFIRM">http://blog.cmsmadesimple.org/2010/05/01/announcing-cms-made-simple-1-7-1-escade/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsmadesimple" name="cms_made_simple">
        <vers num="0.10" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.11" edition="beta5" />
        <vers num="0.11" edition="beta6" />
        <vers num="0.11.1" />
        <vers num="0.11.2" />
        <vers num="0.12" edition="beta1" />
        <vers num="0.12" edition="beta2" />
        <vers num="0.12.1" />
        <vers num="0.12.2" />
        <vers num="0.13" edition="beta1" />
        <vers num="0.13" edition="beta2" />
        <vers num="0.13" edition="beta3" />
        <vers num="1.0" edition="beta1" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0" edition="beta3" />
        <vers num="1.0" edition="beta4" />
        <vers num="1.0" edition="beta5" />
        <vers num="1.0" edition="beta6" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1" edition="rc1" />
        <vers num="1.1" edition="rc2" />
        <vers num="1.1" edition="rc3" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3.1" />
        <vers num="1.1.4.1" />
        <vers num="1.2" edition="beta1" />
        <vers num="1.2" edition="beta2" />
        <vers num="1.2" edition="beta3" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" edition="beta1" />
        <vers num="1.3" edition="beta2" />
        <vers num="1.3.1" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4.1" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers prev="1" num="1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1486" published="2010-04-22" name="CVE-2010-1486" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39587" source="BID">39587</ref>
      <ref url="http://www.coresecurity.com/content/cactushop-xss-persistent-vulnerability" source="MISC">http://www.coresecurity.com/content/cactushop-xss-persistent-vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cactushop" name="cactushop">
        <vers num="3" />
        <vers num="4" />
        <vers num="4.1" />
        <vers num="4.5" />
        <vers num="4.6" />
        <vers num="4.7" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers prev="1" num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1487" published="2010-04-20" name="CVE-2010-1487" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39525" source="BID">39525</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21427073" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21427073</ref>
      <ref url="http://secunia.com/advisories/39507" source="SECUNIA" adv="1">39507</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14725" source="OVAL">oval:org.mitre.oval:def:14725</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="7.0" />
        <vers num="8.0" />
        <vers num="8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1488" published="2010-04-20" name="CVE-2010-1488" modified="2010-04-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The proc_oom_score function in fs/proc/base.c in the Linux kernel before 2.6.34-rc4 uses inappropriate data structures during selection of a candidate for the OOM killer, which might allow local users to cause a denial of service via unspecified patterns of task creation.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=582068" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=582068</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/04/14/1" source="MLIST">[oss-security] 20100414 Couple of kernel issues</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.34-rc4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.34-rc4</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b95c35e76b29ba812e5dabdd91592e25ec640e93" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b95c35e76b29ba812e5dabdd91592e25ec640e93</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers prev="1" num="2.6.34" edition="rc1" />
        <vers prev="1" num="2.6.34" edition="rc2" />
        <vers prev="1" num="2.6.34" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1489" published="2010-04-20" name="CVE-2010-1489" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://p42.us/ie8xss/Abusing_IE8s_XSS_Filters.pdf" source="MISC">http://p42.us/ie8xss/Abusing_IE8s_XSS_Filters.pdf</ref>
      <ref url="http://p42.us/ie8xss/" source="MISC">http://p42.us/ie8xss/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12638" source="OVAL">oval:org.mitre.oval:def:12638</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2010/04/19/guidance-on-internet-explorer-xss-filter.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2010/04/19/guidance-on-internet-explorer-xss-filter.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1490" published="2010-04-21" name="CVE-2010-1490" modified="2010-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57937" source="XF">ibm-cognos-unspecified(57937)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0947" source="VUPEN" adv="1">ADV-2010-0947</ref>
      <ref url="http://www.securityfocus.com/bid/39580" source="BID">39580</ref>
      <ref url="http://secunia.com/advisories/39451" source="SECUNIA" adv="1">39451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="cognos_8_business_intelligence">
        <vers prev="1" num="8.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1491" published="2010-04-23" name="CVE-2010-1491" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39607" source="BID">39607</ref>
      <ref url="http://www.exploit-db.com/exploits/12318" source="EXPLOIT-DB">12318</ref>
      <ref url="http://secunia.com/advisories/39533" source="SECUNIA" adv="1">39533</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlammsblog-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlammsblog-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mms.pipp" name="com_mmsblog">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1492" published="2010-04-23" name="CVE-2010-1492" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in help/frameRight.php in Elastix 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id_nodo parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39610" source="BID">39610</ref>
      <ref url="http://secunia.com/advisories/39164" source="SECUNIA" adv="1">39164</ref>
      <ref url="http://osvdb.org/63936" source="OSVDB">63936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="palosanto" name="elastix">
        <vers num="1.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1493" published="2010-04-23" name="CVE-2010-1493" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57694" source="XF">comawdwall-itemid-sql-injection(57694)</ref>
      <ref url="http://www.securityfocus.com/bid/38194" source="BID">38194</ref>
      <ref url="http://www.osvdb.org/63942" source="OSVDB">63942</ref>
      <ref url="http://www.exploit-db.com/exploits/12113" source="EXPLOIT-DB">12113</ref>
      <ref url="http://www.awdwall.com/index.php/awdwall-updates-logs-" source="CONFIRM">http://www.awdwall.com/index.php/awdwall-updates-logs-</ref>
      <ref url="http://secunia.com/advisories/39553" source="SECUNIA" adv="1">39553</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaawdwall-lfisql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaawdwall-lfisql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awdsolution" name="com_awdwall">
        <vers prev="1" num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1494" published="2010-04-23" name="CVE-2010-1494" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57693" source="XF">comawdwall-controller-file-include(57693)</ref>
      <ref url="http://www.securityfocus.com/bid/39331" source="BID">39331</ref>
      <ref url="http://www.osvdb.org/63943" source="OSVDB">63943</ref>
      <ref url="http://www.exploit-db.com/exploits/12113" source="EXPLOIT-DB">12113</ref>
      <ref url="http://www.awdwall.com/index.php/awdwall-updates-logs-" source="MISC" adv="1">http://www.awdwall.com/index.php/awdwall-updates-logs-</ref>
      <ref url="http://secunia.com/advisories/39553" source="SECUNIA" adv="1">39553</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaawdwall-lfisql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaawdwall-lfisql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="awdsolution" name="com_awdwall">
        <vers num="1.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1495" published="2010-04-23" name="CVE-2010-1495" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0929" source="VUPEN" adv="1">ADV-2010-0929</ref>
      <ref url="http://www.securityfocus.com/bid/39550" source="BID">39550</ref>
      <ref url="http://www.exploit-db.com/exploits/12286" source="EXPLOIT-DB">12286</ref>
      <ref url="http://secunia.com/advisories/39523" source="SECUNIA" adv="1">39523</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlamatamko-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlamatamko-lfi.txt</ref>
      <ref url="http://osvdb.org/63918" source="OSVDB">63918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matamko" name="com_matamko">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1496" published="2010-04-23" name="CVE-2010-1496" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57910" source="XF">joltcard-index-sql-injection(57910)</ref>
      <ref url="http://www.xenuser.org/documents/security/joomla_com_joltcard_sqli.txt" source="MISC">http://www.xenuser.org/documents/security/joomla_com_joltcard_sqli.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39541" source="BID">39541</ref>
      <ref url="http://www.osvdb.org/63913" source="OSVDB">63913</ref>
      <ref url="http://www.exploit-db.com/exploits/12269" source="EXPLOIT-DB">12269</ref>
      <ref url="http://secunia.com/advisories/39520" source="SECUNIA" adv="1">39520</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajoltcard-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajoltcard-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jolt" name="com_joltcard">
        <vers num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1497" published="2010-04-23" name="CVE-2010-1497" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57918" source="XF">dlstats-id-xss(57918)</ref>
      <ref url="http://www.xenuser.org/documents/security/dl_stats_multiple_vulnerabilities.txt" source="MISC">http://www.xenuser.org/documents/security/dl_stats_multiple_vulnerabilities.txt</ref>
      <ref url="http://www.xenuser.org/2010/04/18/dl_stats-multiple-vulnerabilities-sqli-xss-unprotected-admin-panel/" source="MISC">http://www.xenuser.org/2010/04/18/dl_stats-multiple-vulnerabilities-sqli-xss-unprotected-admin-panel/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0939" source="VUPEN" adv="1">ADV-2010-0939</ref>
      <ref url="http://www.securityfocus.com/bid/39592" source="BID">39592</ref>
      <ref url="http://www.osvdb.org/63909" source="OSVDB">63909</ref>
      <ref url="http://www.exploit-db.com/exploits/12280" source="EXPLOIT-DB">12280</ref>
      <ref url="http://secunia.com/advisories/39496" source="SECUNIA" adv="1">39496</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/dlstats-sqlxssadmin.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/dlstats-sqlxssadmin.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clausvb" name="dl_stats">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1498" published="2010-04-23" name="CVE-2010-1498" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57917" source="XF">dlstats-id-sql-injection(57917)</ref>
      <ref url="http://www.xenuser.org/documents/security/dl_stats_multiple_vulnerabilities.txt" source="MISC">http://www.xenuser.org/documents/security/dl_stats_multiple_vulnerabilities.txt</ref>
      <ref url="http://www.xenuser.org/2010/04/18/dl_stats-multiple-vulnerabilities-sqli-xss-unprotected-admin-panel/" source="MISC">http://www.xenuser.org/2010/04/18/dl_stats-multiple-vulnerabilities-sqli-xss-unprotected-admin-panel/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0939" source="VUPEN" adv="1">ADV-2010-0939</ref>
      <ref url="http://www.securityfocus.com/bid/39592" source="BID">39592</ref>
      <ref url="http://www.osvdb.org/63908" source="OSVDB">63908</ref>
      <ref url="http://www.osvdb.org/63907" source="OSVDB">63907</ref>
      <ref url="http://www.exploit-db.com/exploits/12280" source="EXPLOIT-DB">12280</ref>
      <ref url="http://secunia.com/advisories/39496" source="SECUNIA" adv="1">39496</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/dlstats-sqlxssadmin.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/dlstats-sqlxssadmin.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clausvb" name="dl_stats">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1499" published="2010-04-23" name="CVE-2010-1499" modified="2010-04-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57979" source="XF">musicbox-id-sql-injection(57979)</ref>
      <ref url="http://www.securityfocus.com/bid/39581" source="BID">39581</ref>
      <ref url="http://www.exploit-db.com/exploits/12303" source="EXPLOIT-DB">12303</ref>
      <ref url="http://secunia.com/advisories/39476" source="SECUNIA" adv="1">39476</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/musicbox33-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/musicbox33-sql.txt</ref>
      <ref url="http://osvdb.org/63927" source="OSVDB">63927</ref>
    </refs>
    <vuln_soft>
      <prod vendor="musicboxv2" name="musicbox">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1500" published="2010-04-23" name="CVE-2010-1500" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and attack vectors, related to a "type confusion error."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11906" source="OVAL">oval:org.mitre.oval:def:11906</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/39443" source="CONFIRM">http://bugs.chromium.org/39443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1501" reject="1" published="2010-04-23" name="CVE-2010-1501" modified="2010-09-28">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1767.  Reason: This candidate is a duplicate of CVE-2010-1767.  Notes: All CVE users should reference CVE-2010-1767 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-1502" published="2010-04-23" name="CVE-2010-1502" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access local files via vectors related to "developer tools."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12041" source="OVAL">oval:org.mitre.oval:def:12041</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40136" source="CONFIRM">http://bugs.chromium.org/40136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1503" published="2010-04-23" name="CVE-2010-1503" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://net-internals URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39667" source="BID">39667</ref>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11244" source="OVAL">oval:org.mitre.oval:def:11244</ref>
      <ref url="http://osvdb.org/63999" source="OSVDB">63999</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40137" source="CONFIRM">http://bugs.chromium.org/40137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1504" published="2010-04-23" name="CVE-2010-1504" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://downloads URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39669" source="BID">39669</ref>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11418" source="OVAL">oval:org.mitre.oval:def:11418</ref>
      <ref url="http://osvdb.org/63998" source="OSVDB">63998</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40138" source="CONFIRM">http://bugs.chromium.org/40138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1505" published="2010-04-23" name="CVE-2010-1505" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11866" source="OVAL">oval:org.mitre.oval:def:11866</ref>
      <ref url="http://osvdb.org/63997" source="OSVDB">63997</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40575" source="CONFIRM">http://bugs.chromium.org/40575</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1506" published="2010-04-23" name="CVE-2010-1506" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11925" source="OVAL">oval:org.mitre.oval:def:11925</ref>
      <ref url="http://osvdb.org/63996" source="OSVDB">63996</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40635" source="CONFIRM">http://bugs.chromium.org/40635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1507" published="2010-09-03" name="CVE-2010-1507" modified="2010-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=598834" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=598834</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=591345" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=591345</ref>
      <ref url="http://www.securityfocus.com/bid/42128" source="BID">42128</ref>
      <ref url="http://support.novell.com/security/cve/CVE-2010-1507.html" source="CONFIRM">http://support.novell.com/security/cve/CVE-2010-1507.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="suse_linux">
        <vers num="11" edition="-" />
        <vers num="11" edition="-:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1508" published="2010-12-09" name="CVE-2010-1508" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Dec/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-12-07-1</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-258/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-258/</ref>
      <ref url="http://www.securitytracker.com/id?1024830" source="SECTRACK">1024830</ref>
      <ref url="http://support.apple.com/kb/HT4447" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4447</ref>
      <ref url="http://secunia.com/secunia_research/2010-72/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-72/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.2.0" />
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.2.0" />
        <vers num="7.2.1" />
        <vers num="7.3" />
        <vers num="7.3.0" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" />
        <vers num="7.4.1" />
        <vers num="7.4.5" />
        <vers num="7.5.0" />
        <vers num="7.5.5" />
        <vers num="7.6.0" />
        <vers num="7.6.1" />
        <vers num="7.6.2" />
        <vers num="7.6.5" />
        <vers num="7.6.6" />
        <vers num="7.6.7" />
        <vers prev="1" num="7.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1509" published="2010-05-14" name="CVE-2010-1509" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58548" source="XF">irfanview-psd-bo(58548)</ref>
      <ref url="http://www.securityfocus.com/bid/40104" source="BID">40104</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511274/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: IrfanView PSD Image Parsing Sign-Extension Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-41" source="MISC" adv="1">http://secunia.com/secunia_research/2010-41</ref>
      <ref url="http://secunia.com/advisories/39036" source="SECUNIA" adv="1">39036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6705" source="OVAL">oval:org.mitre.oval:def:6705</ref>
      <ref url="http://osvdb.org/64627" source="OSVDB">64627</ref>
      <ref url="http://irfanview.com/main_history.htm" source="CONFIRM">http://irfanview.com/main_history.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="1.70" />
        <vers num="1.75" />
        <vers num="1.80" />
        <vers num="1.85" />
        <vers num="1.90" />
        <vers num="1.95" />
        <vers num="1.97" />
        <vers num="1.98" />
        <vers num="1.98a" />
        <vers num="1.99" />
        <vers num="2.00" />
        <vers num="2.05" />
        <vers num="2.07" />
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.15" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.20" />
        <vers num="2.22" />
        <vers num="2.25" />
        <vers num="2.27" />
        <vers num="2.30" />
        <vers num="2.32" />
        <vers num="2.35" />
        <vers num="2.37" />
        <vers num="2.40" />
        <vers num="2.50" />
        <vers num="2.52" />
        <vers num="2.55" />
        <vers num="2.60" />
        <vers num="2.62" />
        <vers num="2.63" />
        <vers num="2.65" />
        <vers num="2.66" />
        <vers num="2.68" />
        <vers num="2.80" />
        <vers num="2.82" />
        <vers num="2.83" />
        <vers num="2.85" />
        <vers num="2.90" />
        <vers num="2.92" />
        <vers num="2.95" />
        <vers num="2.97" />
        <vers num="2.98" />
        <vers num="3.00" />
        <vers num="3.02" />
        <vers num="3.05" />
        <vers num="3.07" />
        <vers num="3.10" />
        <vers num="3.12" />
        <vers num="3.15" />
        <vers num="3.17" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.25" />
        <vers num="3.30" />
        <vers num="3.33" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.50" />
        <vers num="3.51" />
        <vers num="3.60" />
        <vers num="3.61" />
        <vers num="3.70" />
        <vers num="3.75" />
        <vers num="3.80" />
        <vers num="3.85" />
        <vers num="3.90" />
        <vers num="3.91" />
        <vers num="3.92" />
        <vers num="3.95" />
        <vers num="3.97" />
        <vers num="3.98" />
        <vers num="3.99" />
        <vers num="4.00" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers prev="1" num="4.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1510" published="2010-05-14" name="CVE-2010-1510" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58549" source="XF">irfanview-rle-psd-bo(58549)</ref>
      <ref url="http://www.securityfocus.com/bid/40105" source="BID">40105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511275/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: IrfanView PSD RLE Decompression Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2010-42" source="MISC" adv="1">http://secunia.com/secunia_research/2010-42</ref>
      <ref url="http://secunia.com/advisories/39036" source="SECUNIA" adv="1">39036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7397" source="OVAL">oval:org.mitre.oval:def:7397</ref>
      <ref url="http://osvdb.org/64628" source="OSVDB">64628</ref>
      <ref url="http://irfanview.com/main_history.htm" source="CONFIRM">http://irfanview.com/main_history.htm</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="irfanview">
        <vers num="1.70" />
        <vers num="1.75" />
        <vers num="1.80" />
        <vers num="1.85" />
        <vers num="1.90" />
        <vers num="1.95" />
        <vers num="1.97" />
        <vers num="1.98" />
        <vers num="1.98a" />
        <vers num="1.99" />
        <vers num="2.00" />
        <vers num="2.05" />
        <vers num="2.07" />
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.15" />
        <vers num="2.17" />
        <vers num="2.18" />
        <vers num="2.20" />
        <vers num="2.22" />
        <vers num="2.25" />
        <vers num="2.27" />
        <vers num="2.30" />
        <vers num="2.32" />
        <vers num="2.35" />
        <vers num="2.37" />
        <vers num="2.40" />
        <vers num="2.50" />
        <vers num="2.52" />
        <vers num="2.55" />
        <vers num="2.60" />
        <vers num="2.62" />
        <vers num="2.63" />
        <vers num="2.65" />
        <vers num="2.66" />
        <vers num="2.68" />
        <vers num="2.80" />
        <vers num="2.82" />
        <vers num="2.83" />
        <vers num="2.85" />
        <vers num="2.90" />
        <vers num="2.92" />
        <vers num="2.95" />
        <vers num="2.97" />
        <vers num="2.98" />
        <vers num="3.00" />
        <vers num="3.02" />
        <vers num="3.05" />
        <vers num="3.07" />
        <vers num="3.10" />
        <vers num="3.12" />
        <vers num="3.15" />
        <vers num="3.17" />
        <vers num="3.20" />
        <vers num="3.21" />
        <vers num="3.25" />
        <vers num="3.30" />
        <vers num="3.33" />
        <vers num="3.35" />
        <vers num="3.36" />
        <vers num="3.50" />
        <vers num="3.51" />
        <vers num="3.60" />
        <vers num="3.61" />
        <vers num="3.70" />
        <vers num="3.75" />
        <vers num="3.80" />
        <vers num="3.85" />
        <vers num="3.90" />
        <vers num="3.91" />
        <vers num="3.92" />
        <vers num="3.95" />
        <vers num="3.97" />
        <vers num="3.98" />
        <vers num="3.99" />
        <vers num="4.00" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers prev="1" num="4.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1511" published="2010-05-17" name="CVE-2010-1511" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58629" source="XF">kde-metalink-file-overwrite(58629)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3096" source="VUPEN" adv="1">ADV-2010-3096</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1144" source="VUPEN" adv="1">ADV-2010-1144</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1142" source="VUPEN" adv="1">ADV-2010-1142</ref>
      <ref url="http://www.ubuntu.com/usn/USN-938-1" source="UBUNTU">USN-938-1</ref>
      <ref url="http://www.securityfocus.com/bid/40141" source="BID">40141</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511294/100/0/threaded" source="BUGTRAQ">20100514 Re: Secunia Research: KDE KGet Insecure File Operation Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511279/100/0/threaded" source="BUGTRAQ">20100513 Secunia Research: KDE KGet Insecure File Operation Vulnerability</ref>
      <ref url="http://www.kde.org/info/security/advisory-20100513-1.txt" source="CONFIRM" adv="1">http://www.kde.org/info/security/advisory-20100513-1.txt</ref>
      <ref url="http://securitytracker.com/id?1023984" source="SECTRACK">1023984</ref>
      <ref url="http://secunia.com/secunia_research/2010-70/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-70/</ref>
      <ref url="http://secunia.com/advisories/39787" source="SECUNIA" adv="1">39787</ref>
      <ref url="http://secunia.com/advisories/39528" source="SECUNIA" adv="1">39528</ref>
      <ref url="http://osvdb.org/64689" source="OSVDB">64689</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127378789518426&amp;w=2" source="MLIST">[oss-security] 20100513 KDENetwork vulnerabilities</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.html" source="FEDORA">FEDORA-2010-18029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde_sc">
        <vers num="2.2.0" />
        <vers num="3.5.10" />
        <vers num="4.0.0" edition="alpha1" />
        <vers num="4.0.0" edition="alpha2" />
        <vers num="4.0.0" edition="beta1" />
        <vers num="4.0.0" edition="beta2" />
        <vers num="4.0.0" edition="beta3" />
        <vers num="4.0.0" edition="beta4" />
        <vers num="4.0.0" edition="rc1" />
        <vers num="4.0.0" edition="rc2" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1.0" edition="alpha1" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="beta2" />
        <vers num="4.1.0" edition="rc" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.80" />
        <vers num="4.1.85" />
        <vers num="4.1.96" />
        <vers num="4.2" edition="beta2" />
        <vers num="4.2" edition="rc" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.3.0" edition="beta1" />
        <vers num="4.3.0" edition="beta3" />
        <vers num="4.3.0" edition="rc1" />
        <vers num="4.3.0" edition="rc2" />
        <vers num="4.3.0" edition="rc3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="4.3.3" />
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="rc1" />
        <vers num="4.4.0" edition="rc2" />
        <vers num="4.4.0" edition="rc3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="4.4.3" />
      </prod>
      <prod vendor="kde" name="kget">
        <vers num="2.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1512" published="2010-05-17" name="CVE-2010-1512" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40142" source="BID" patch="1">40142</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0116" source="VUPEN">ADV-2011-0116</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1229" source="VUPEN">ADV-2010-1229</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1228" source="VUPEN">ADV-2010-1228</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511280/100/0/threaded" source="BUGTRAQ">20100513 Secunia Research: aria2 metalink "name" Directory Traversal Vulnerability</ref>
      <ref url="http://www.osvdb.org/64592" source="OSVDB">64592</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:106" source="MANDRIVA">MDVSA-2010:106</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2047" source="DEBIAN">DSA-2047</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-04.xml" source="GENTOO">GLSA-201101-04</ref>
      <ref url="http://secunia.com/secunia_research/2010-71/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-71/</ref>
      <ref url="http://secunia.com/advisories/42906" source="SECUNIA">42906</ref>
      <ref url="http://secunia.com/advisories/39872" source="SECUNIA">39872</ref>
      <ref url="http://secunia.com/advisories/39529" source="SECUNIA" adv="1">39529</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041758.html" source="FEDORA">FEDORA-2010-8915</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041754.html" source="FEDORA">FEDORA-2010-8908</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041753.html" source="FEDORA">FEDORA-2010-8905</ref>
      <ref url="http://downloads.sourceforge.net/project/aria2/stable/aria2-1.9.3/NEWS" source="CONFIRM">http://downloads.sourceforge.net/project/aria2/stable/aria2-1.9.3/NEWS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tatsuhiro_tsujikawa" name="aria2">
        <vers num="0.1.0" />
        <vers num="0.10.0" />
        <vers num="0.10.0+1" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.2+1" />
        <vers num="0.11.0" />
        <vers num="0.11.1" />
        <vers num="0.11.1+1" />
        <vers num="0.11.2" />
        <vers num="0.11.3" />
        <vers num="0.11.4" />
        <vers num="0.11.5" />
        <vers num="0.12.0" />
        <vers num="0.12.1" />
        <vers num="0.13.0" />
        <vers num="0.13.0+1" />
        <vers num="0.13.1" />
        <vers num="0.13.1+1" />
        <vers num="0.13.1+2" />
        <vers num="0.13.2" />
        <vers num="0.13.2+1" />
        <vers num="0.14.0" />
        <vers num="0.14.0+1" />
        <vers num="0.15.0" />
        <vers num="0.15.1" />
        <vers num="0.15.1+1" />
        <vers num="0.15.1+2" />
        <vers num="0.15.2" />
        <vers num="0.15.3" />
        <vers num="0.16.0" />
        <vers num="0.16.1" />
        <vers num="0.16.2" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.1+1" />
        <vers num="0.2.1+2" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.1+1" />
        <vers num="0.3.1+2" />
        <vers num="0.3.2" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.5.0" />
        <vers num="0.5.0+1" />
        <vers num="0.5.0+2" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.6.0" />
        <vers num="0.6.0+1" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.9.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.5.0" />
        <vers num="1.5.0b+20090716" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.9.0" />
        <vers num="1.9.1" />
        <vers prev="1" num="1.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1513" published="2010-05-26" name="CVE-2010-1513" modified="2010-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://ziproxy.sourceforge.net/#news" source="CONFIRM" adv="1">http://ziproxy.sourceforge.net/#news</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511424/100/0/threaded" source="BUGTRAQ">20100524 Secunia Research: Ziproxy Two Integer Overflow Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-75/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-75/</ref>
      <ref url="http://secunia.com/advisories/39941" source="SECUNIA" adv="1">39941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="daniel_mealha_cabrita" name="ziproxy">
        <vers num="1.1" />
        <vers num="1.2" edition="b" />
        <vers num="1.3" edition="b" />
        <vers num="1.3" edition="beta" />
        <vers num="1.3" edition="c" />
        <vers num="1.3" edition="d" />
        <vers num="1.4.0" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.9.0" />
        <vers num="2.0.0" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.5" edition="beta" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.8" edition="beta" />
        <vers num="2.4.8" edition="beta2" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.9" edition="beta" />
        <vers num="2.6.0" />
        <vers num="2.6.9" edition="beta" />
        <vers num="2.6.9" edition="beta2" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.7.9" edition="beta" />
        <vers num="2.7.9" edition="beta2" />
        <vers num="2.7.9" edition="beta3" />
        <vers prev="1" num="3.0.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1514" published="2010-06-15" name="CVE-2010-1514" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40544" source="BID">40544</ref>
      <ref url="http://secunia.com/secunia_research/2010-57/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-57/</ref>
      <ref url="http://secunia.com/advisories/39680" source="SECUNIA" adv="1">39680</ref>
      <ref url="http://holisticinfosec.org/content/view/148/45/" source="MISC">http://holisticinfosec.org/content/view/148/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomatocms" name="tomatocms">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.3.1430" />
        <vers num="2.0.3.1622" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers prev="1" num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1515" published="2010-06-15" name="CVE-2010-1515" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword parameter in conjunction with a /admin/multimedia/set/list PATH_INFO; the (4) keyword or (5) fileId parameter in conjunction with a /admin/multimedia/file/list PATH_INFO; or the (6) name, (7) email, or (8) address parameter in conjunction with a /admin/ad/client/list PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40544" source="BID">40544</ref>
      <ref url="http://secunia.com/secunia_research/2010-58/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-58/</ref>
      <ref url="http://secunia.com/advisories/39680" source="SECUNIA" adv="1">39680</ref>
      <ref url="http://holisticinfosec.org/content/view/148/45/" source="MISC">http://holisticinfosec.org/content/view/148/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomatocms" name="tomatocms">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.3.1430" />
        <vers num="2.0.3.1622" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers prev="1" num="2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1516" published="2010-08-17" name="CVE-2010-1516" modified="2010-08-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513102/100/0/threaded" source="BUGTRAQ">20100813 Secunia Research: SWFTools Two Integer Overflow Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-80/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-80/</ref>
      <ref url="http://secunia.com/advisories/39970" source="SECUNIA" adv="1">39970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swftools" name="swftools">
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1517" published="2010-08-02" name="CVE-2010-1517" modified="2010-08-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2010-85/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-85/</ref>
      <ref url="http://secunia.com/advisories/40161" source="SECUNIA" adv="1">40161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigabyte" name="dldrv2_activex_control">
        <vers num="1.4.206.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1518" published="2010-08-02" name="CVE-2010-1518" modified="2010-08-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via the item argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2010-86/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-86/</ref>
      <ref url="http://secunia.com/advisories/40161" source="SECUNIA" adv="1">40161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigabyte" name="dldrv2_activex_control">
        <vers num="1.4.206.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1519" published="2010-08-16" name="CVE-2010-1519" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in glpng.c in glpng 1.45 allow context-dependent attackers to execute arbitrary code via a crafted PNG image, related to (1) the pngLoadRawF function and (2) the pngLoadF function, leading to heap-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513022/100/0/threaded" source="BUGTRAQ">20100811 Secunia Research: glpng PNG Processing Two Integer Overflow Vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:179" source="MANDRIVA">MDVSA-2010:179</ref>
      <ref url="http://secunia.com/secunia_research/2010-87/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-87/</ref>
      <ref url="http://secunia.com/advisories/40354" source="SECUNIA" adv="1">40354</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glpng" name="glpng">
        <vers num="1.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1520" published="2010-06-30" name="CVE-2010-1520" modified="2010-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in logout.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.taskfreak.com/original/versions" source="CONFIRM" patch="1">http://www.taskfreak.com/original/versions</ref>
      <ref url="http://www.securityfocus.com/bid/41221" source="BID">41221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512078/100/0/threaded" source="BUGTRAQ">20100629 Secunia Research: TaskFreak "tznMessage" Cross-Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-78/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-78/</ref>
      <ref url="http://secunia.com/advisories/40025" source="SECUNIA" adv="1">40025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak!">
        <vers num="0.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers prev="1" num="0.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1521" published="2010-06-30" name="CVE-2010-1521" modified="2010-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.taskfreak.com/original/versions" source="CONFIRM" patch="1">http://www.taskfreak.com/original/versions</ref>
      <ref url="http://www.securityfocus.com/bid/41218" source="BID">41218</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512077/100/0/threaded" source="BUGTRAQ">20100629 Secunia Research: TaskFreak "password" SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-79/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-79/</ref>
      <ref url="http://secunia.com/advisories/40025" source="SECUNIA" adv="1">40025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak!">
        <vers num="0.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers prev="1" num="0.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1522" published="2010-07-02" name="CVE-2010-1522" modified="2010-07-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the BookLibrary Basic (com_booklibrary) component 1.5.3 before 1.5.3_2010_06_20 for Joomla! allow remote attackers to execute arbitrary SQL commands via the bid[] parameter in a (1) lend_request or (2) save_lend_request action to index.php, the id parameter in a (3) mdownload or (4) downitsf action to index.php, or (5) the searchtext parameter in a search action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ordasoft.com/Download/View-document-details/3-BookLibrary-1.5.3-Basic-for-Joomla-1.5.html" source="MISC" patch="1">http://ordasoft.com/Download/View-document-details/3-BookLibrary-1.5.3-Basic-for-Joomla-1.5.html</ref>
      <ref url="http://ordasoft.com/Download/Download-document/3-BookLibrary-1.5.3-Basic-for-Joomla-1.5.html" source="MISC" patch="1">http://ordasoft.com/Download/Download-document/3-BookLibrary-1.5.3-Basic-for-Joomla-1.5.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59966" source="XF">booklibrary-index-sql-injection(59966)</ref>
      <ref url="http://www.securityfocus.com/bid/41264" source="BID">41264</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512094/100/0/threaded" source="BUGTRAQ">20100630 Secunia Research: Joomla BookLibrary Component Four SQL Injection Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-84/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-84/</ref>
      <ref url="http://secunia.com/advisories/40131" source="SECUNIA" adv="1">40131</ref>
      <ref url="http://osvdb.org/65879" source="OSVDB">65879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ordasoft" name="com_booklibrary">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1523" published="2010-11-05" name="CVE-2010-1523" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arbitrary code via a crafted VP6 (1) video file or (2) video stream.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/44466" source="BID">44466</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514484/100/0/threaded" source="BUGTRAQ">20101027 Secunia Research: Winamp VP6 Content Parsing Buffer Overflow Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-95/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-95/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12056" source="OVAL">oval:org.mitre.oval:def:12056</ref>
      <ref url="http://forums.winamp.com/showthread.php?t=322995" source="CONFIRM">http://forums.winamp.com/showthread.php?t=322995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="0.20a" />
        <vers num="0.92" />
        <vers num="1.006" />
        <vers num="1.90" />
        <vers num="2.0" />
        <vers num="2.10" />
        <vers num="2.24" />
        <vers num="2.4" />
        <vers num="2.50" />
        <vers num="2.5e" />
        <vers num="2.6" />
        <vers num="2.60" edition="" />
        <vers num="2.60" edition=":full" />
        <vers num="2.60" edition=":lite" />
        <vers num="2.61" edition="" />
        <vers num="2.61" edition=":full" />
        <vers num="2.62" edition="" />
        <vers num="2.62" edition=":standard" />
        <vers num="2.64" edition="" />
        <vers num="2.64" edition=":standard" />
        <vers num="2.65" />
        <vers num="2.6x" />
        <vers num="2.70" edition="" />
        <vers num="2.70" edition=":full" />
        <vers num="2.71" />
        <vers num="2.72" />
        <vers num="2.73" edition="" />
        <vers num="2.73" edition=":full" />
        <vers num="2.74" />
        <vers num="2.75" />
        <vers num="2.76" />
        <vers num="2.77" />
        <vers num="2.78" />
        <vers num="2.79" />
        <vers num="2.7x" />
        <vers num="2.80" />
        <vers num="2.81" />
        <vers num="2.9" />
        <vers num="2.90" />
        <vers num="2.91" />
        <vers num="2.92" />
        <vers num="2.95" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.03a" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
        <vers num="5.07" />
        <vers num="5.08" edition="c" />
        <vers num="5.08" edition="d" />
        <vers num="5.08" edition="e" />
        <vers num="5.08c" />
        <vers num="5.08d" />
        <vers num="5.08e" />
        <vers num="5.09" />
        <vers num="5.091" />
        <vers num="5.093" />
        <vers num="5.094" />
        <vers num="5.1" edition="-" />
        <vers num="5.1" edition="-:surround" />
        <vers num="5.11" />
        <vers num="5.111" />
        <vers num="5.112" />
        <vers num="5.12" />
        <vers num="5.13" />
        <vers num="5.2" />
        <vers num="5.21" />
        <vers num="5.22" />
        <vers num="5.23" />
        <vers num="5.24" />
        <vers num="5.3" />
        <vers num="5.31" />
        <vers num="5.32" />
        <vers num="5.33" />
        <vers num="5.34" />
        <vers num="5.35" />
        <vers num="5.36" />
        <vers num="5.5" />
        <vers num="5.51" />
        <vers num="5.52" />
        <vers num="5.53" />
        <vers num="5.531" />
        <vers num="5.54" />
        <vers num="5.541" />
        <vers num="5.55" />
        <vers num="5.551" />
        <vers num="5.552" />
        <vers num="5.56" />
        <vers num="5.57" />
        <vers num="5.572" />
        <vers num="5.58" />
        <vers prev="1" num="5.581" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1524" published="2010-08-17" name="CVE-2010-1524" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via unspecified vectors related to allocation of an array of pointers and "string indexing," which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-35/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-35/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1525" published="2010-08-17" name="CVE-2010-1525" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2010&amp;suid=20100727_01</ref>
      <ref url="http://www.securityfocus.com/bid/41928" source="BID">41928</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21440812" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21440812</ref>
      <ref url="http://secunia.com/secunia_research/2010-49/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-49/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="keyview_export_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_filter_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
      <prod vendor="autonomy" name="keyview_viewer_sdk">
        <vers num="10.4" />
        <vers num="10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1526" published="2010-08-24" name="CVE-2010-1526" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2010-102/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-102/</ref>
      <ref url="http://secunia.com/advisories/40792" source="SECUNIA" adv="1">40792</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mono-project" name="libgdiplus">
        <vers num="2.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1527" published="2010-08-23" name="CVE-2010-1527" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.</descript>
    </desc>
    <sols>
      <sol source="nvd">Fix is included in "iPrint Client for Windows XP/Vista/Win7 5.44" </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61220" source="XF">novell-iprint-callbackurl-bo(61220)</ref>
      <ref url="http://www.securityfocus.com/bid/42576" source="BID">42576</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7006679" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7006679</ref>
      <ref url="http://secunia.com/secunia_research/2010-104/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-104/</ref>
      <ref url="http://secunia.com/advisories/40805" source="SECUNIA" adv="1">40805</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11973" source="OVAL">oval:org.mitre.oval:def:11973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="iprint">
        <vers num="4.26" />
        <vers num="4.27" />
        <vers num="4.28" />
        <vers num="4.30" />
        <vers num="4.32" />
        <vers num="4.34" />
        <vers num="4.36" />
        <vers num="4.38" />
        <vers num="5.04" />
        <vers num="5.12" />
        <vers num="5.20b" />
        <vers num="5.30" />
        <vers num="5.32" />
        <vers num="5.40" />
        <vers prev="1" num="5.42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1528" published="2010-04-26" name="CVE-2010-1528" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57515" source="XF">uigaproxy-template-file-include(57515)</ref>
      <ref url="http://www.securityfocus.com/bid/39365" source="BID">39365</ref>
      <ref url="http://www.osvdb.org/63528" source="OSVDB">63528</ref>
      <ref url="http://www.exploit-db.com/exploits/12049" source="EXPLOIT-DB">12049</ref>
      <ref url="http://secunia.com/advisories/39313" source="SECUNIA" adv="1">39313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uiga" name="proxy">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1529" published="2010-04-26" name="CVE-2010-1529" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57588" source="XF">freestylefaqlite-faqid-sql-injection(57588)</ref>
      <ref url="http://www.securityfocus.com/bid/39220" source="BID">39220</ref>
      <ref url="http://www.exploit-db.com/exploits/12078" source="EXPLOIT-DB">12078</ref>
      <ref url="http://secunia.com/advisories/39288" source="SECUNIA" adv="1">39288</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlafreestyle-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlafreestyle-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freestyle" name="faqs_lite">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1530" published="2010-04-26" name="CVE-2010-1530" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39304" source="BID" patch="1">39304</ref>
      <ref url="http://drupal.org/node/764998" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/764998</ref>
      <ref url="http://drupal.org/node/764906" source="CONFIRM" patch="1">http://drupal.org/node/764906</ref>
      <ref url="http://secunia.com/advisories/39361" source="SECUNIA" adv="1">39361</ref>
      <ref url="http://osvdb.org/63589" source="OSVDB">63589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reyero" name="i18n">
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-1.0" edition="beta4" />
        <vers num="6.x-1.0" edition="beta6" />
        <vers num="6.x-1.0" edition="dev" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1531" published="2010-04-26" name="CVE-2010-1531" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57512" source="XF">redshop-view-file-include(57512)</ref>
      <ref url="http://www.securityfocus.com/bid/39206" source="BID">39206</ref>
      <ref url="http://www.osvdb.org/63535" source="OSVDB">63535</ref>
      <ref url="http://www.exploit-db.com/exploits/12054" source="EXPLOIT-DB">12054</ref>
      <ref url="http://secunia.com/advisories/39343" source="SECUNIA" adv="1">39343</ref>
      <ref url="http://redcomponent.com/redshop/redshop-changelog" source="MISC">http://redcomponent.com/redshop/redshop-changelog</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaredshop-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaredshop-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redcomponent" name="com_redshop">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1532" published="2010-04-26" name="CVE-2010-1532" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39348" source="BID">39348</ref>
      <ref url="http://www.exploit-db.com/exploits/12118" source="EXPLOIT-DB">12118</ref>
      <ref url="http://secunia.com/advisories/39226" source="SECUNIA" adv="1">39226</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlapowermail-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlapowermail-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="givesight" name="com_powermail">
        <vers num="1.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1533" published="2010-04-26" name="CVE-2010-1533" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/12142" source="EXPLOIT-DB">12142</ref>
      <ref url="http://secunia.com/advisories/39258" source="SECUNIA" adv="1">39258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peter_hocherl" name="com_tweetla">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1534" published="2010-04-26" name="CVE-2010-1534" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57534" source="XF">shoutbox-controller-file-include(57534)</ref>
      <ref url="http://www.securityfocus.com/bid/39213" source="BID">39213</ref>
      <ref url="http://www.exploit-db.com/exploits/12067" source="EXPLOIT-DB">12067</ref>
      <ref url="http://secunia.com/advisories/39352" source="SECUNIA" adv="1">39352</ref>
      <ref url="http://osvdb.org/63562" source="OSVDB">63562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla.batjo" name="com_shoutbox">
        <vers num="1.2" edition="beta2" />
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1535" published="2010-04-26" name="CVE-2010-1535" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/12151" source="EXPLOIT-DB">12151</ref>
      <ref url="http://secunia.com/advisories/39254" source="SECUNIA" adv="1">39254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="peter_hocherl" name="com_travelbook">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1536" published="2010-04-26" name="CVE-2010-1536" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthis privileges, to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38513" source="BID" patch="1">38513</ref>
      <ref url="http://drupal.org/node/731578" source="CONFIRM" patch="1">http://drupal.org/node/731578</ref>
      <ref url="http://drupal.org/node/731576" source="CONFIRM" patch="1">http://drupal.org/node/731576</ref>
      <ref url="http://drupal.org/node/731568" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/731568</ref>
      <ref url="http://secunia.com/advisories/38818" source="SECUNIA" adv="1">38818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mearra" name="addthis">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.x" edition="dev" />
        <vers num="5.x-2.0" edition="beta1" />
        <vers num="5.x-2.0" edition="beta2" />
        <vers num="5.x-2.0" edition="beta3" />
        <vers num="5.x-2.0" edition="beta5" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.x" edition="dev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.x" edition="dev" />
        <vers num="6.x-2.0" edition="beta" />
        <vers num="6.x-2.0" edition="beta1" />
        <vers num="6.x-2.0" edition="beta2" />
        <vers num="6.x-2.0" edition="beta3" />
        <vers num="6.x-2.1" />
        <vers num="6.x-2.2" />
        <vers num="6.x-2.3" />
        <vers num="6.x-2.4" />
        <vers num="6.x-2.5" />
        <vers num="6.x-2.6" />
        <vers num="6.x-2.7" />
        <vers num="6.x-2.8" />
        <vers num="6.x-2.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1537" published="2010-04-26" name="CVE-2010-1537" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_global parameter to (1) firstvisit.php, (2) newfolder.php, (3) showfolders.php, (4) newlang.php, (5) showinnerfolder.php, (6) writecode.php, and (7) showcode.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56579" source="XF">phpcdb-langglobal-file-include(56579)</ref>
      <ref url="http://www.securityfocus.com/bid/38507" source="BID">38507</ref>
      <ref url="http://www.exploit-db.com/exploits/11585" source="EXPLOIT-DB">11585</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/phpcdb-lfi.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/phpcdb-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francois_bissonnette" name="phpcdb">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1538" published="2010-04-26" name="CVE-2010-1538" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56578" source="XF">phpraincheck-printraincheck-sql-injection(56578)</ref>
      <ref url="http://www.securityfocus.com/bid/38521" source="BID">38521</ref>
      <ref url="http://www.exploit-db.com/exploits/11586" source="EXPLOIT-DB">11586</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/phpraincheck-sql.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/phpraincheck-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluestrikeweb" name="phpraincheck">
        <vers prev="1" num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1539" published="2010-04-26" name="CVE-2010-1539" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comment field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38520" source="BID" patch="1">38520</ref>
      <ref url="http://drupal.org/node/731648" source="CONFIRM" patch="1">http://drupal.org/node/731648</ref>
      <ref url="http://drupal.org/node/731644" source="CONFIRM" patch="1">http://drupal.org/node/731644</ref>
      <ref url="http://drupal.org/node/731624" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/731624</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56638" source="XF">workflow-comment-xss(56638)</ref>
      <ref url="http://secunia.com/advisories/38825" source="SECUNIA" adv="1">38825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_vandyk" name="workflow">
        <vers num="5.x-2.0" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.2" />
        <vers num="5.x-2.3" />
        <vers num="5.x-2.4" />
        <vers num="5.x-2.5" />
        <vers num="5.x-2.x" edition="dev" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.0" edition="rc3" />
        <vers num="6.x-1.0" edition="rc4" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1540" published="2010-04-26" name="CVE-2010-1540" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38530" source="BID">38530</ref>
      <ref url="http://www.exploit-db.com/exploits/11625" source="EXPLOIT-DB">11625</ref>
      <ref url="http://secunia.com/advisories/38777" source="SECUNIA" adv="1">38777</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myblog" name="com_myblog">
        <vers num="3.0.329" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1541" published="2010-04-26" name="CVE-2010-1541" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38505" source="BID">38505</ref>
      <ref url="http://secunia.com/advisories/38635" source="SECUNIA" adv="1">38635</ref>
      <ref url="http://osvdb.org/62672" source="OSVDB">62672</ref>
      <ref url="http://osvdb.org/62671" source="OSVDB">62671</ref>
      <ref url="http://holisticinfosec.org/content/view/135/45/" source="MISC">http://holisticinfosec.org/content/view/135/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dragonfrugal" name="dfd_cart">
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.192" />
        <vers num="1.193" />
        <vers num="1.194" />
        <vers num="1.195" />
        <vers num="1.196" />
        <vers num="1.197" />
        <vers prev="1" num="1.198" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1542" published="2010-04-26" name="CVE-2010-1542" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks or (2) change unspecified settings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/38635" source="SECUNIA" adv="1">38635</ref>
      <ref url="http://osvdb.org/62673" source="OSVDB">62673</ref>
      <ref url="http://holisticinfosec.org/content/view/135/45/" source="MISC">http://holisticinfosec.org/content/view/135/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dragonfrugal" name="dfd_cart">
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.192" />
        <vers num="1.193" />
        <vers num="1.194" />
        <vers num="1.195" />
        <vers num="1.196" />
        <vers num="1.197" />
        <vers prev="1" num="1.198" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1543" published="2010-04-26" name="CVE-2010-1543" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/731682" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/731682</ref>
      <ref url="http://drupal.org/node/731018" source="CONFIRM" patch="1">http://drupal.org/node/731018</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56635" source="XF">etracker-url-xss(56635)</ref>
      <ref url="http://www.securityfocus.com/bid/38514" source="BID">38514</ref>
      <ref url="http://secunia.com/advisories/38826" source="SECUNIA" adv="1">38826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etracker" name="etracker">
        <vers num="6.x-1.0" />
        <vers prev="1" num="6.x-1.1" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1544" published="2010-04-26" name="CVE-2010-1544" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38488" source="BID">38488</ref>
      <ref url="http://secunia.com/advisories/38778" source="SECUNIA" adv="1">38778</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/rcadcm425-dos.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/rcadcm425-dos.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acme" name="micro_httpd">
        <vers num="" />
      </prod>
      <prod vendor="rca" name="digital_cable_modem">
        <vers num="dcm425" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1546" published="2010-05-21" name="CVE-2010-1546" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with "administer page manager" privileges, to execute arbitrary PHP code via input to a text area, related to (1) the page_manager_page_import_subtask_validate function in page_manager/plugins/tasks/page.admin.inc and (2) the page_manager_handler_import_validate function in page_manager/page_manager.admin.inc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40285" source="BID" patch="1">40285</ref>
      <ref url="http://drupal.org/node/803944" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/803944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58723" source="XF">chaos-tool-import-code-execution(58723)</ref>
      <ref url="http://www.madirish.net/?article=458" source="MISC">http://www.madirish.net/?article=458</ref>
      <ref url="http://secunia.com/advisories/39884" source="SECUNIA" adv="1">39884</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/May/272" source="FULLDISC">20100520 Drupal Chaos Tools Suite (Ctools) Module Multiple Vulns</ref>
      <ref url="http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/plugins/tasks/page.admin.inc?view=log" source="CONFIRM">http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/plugins/tasks/page.admin.inc?view=log</ref>
      <ref url="http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/plugins/tasks/page.admin.inc?r1=1.18.2.6&amp;r2=1.18.2.7" source="CONFIRM">http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/plugins/tasks/page.admin.inc?r1=1.18.2.6&amp;r2=1.18.2.7</ref>
      <ref url="http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/page_manager.admin.inc?view=log" source="CONFIRM">http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/page_manager.admin.inc?view=log</ref>
      <ref url="http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/page_manager.admin.inc?r1=1.27.2.9&amp;r2=1.27.2.10" source="CONFIRM">http://drupalcode.org/viewvc/drupal/contributions/modules/ctools/page_manager/page_manager.admin.inc?r1=1.27.2.9&amp;r2=1.27.2.10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angrydonuts" name="ctools">
        <vers num="6.x-1.0" edition="alpha1" />
        <vers num="6.x-1.0" edition="alpha2" />
        <vers num="6.x-1.0" edition="alpha3" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-1.0" edition="beta4" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1547" published="2010-05-21" name="CVE-2010-1547" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable a page via a q=admin/build/pages/nojs/enable/ value or (2) disable a page via a q=admin/build/pages/nojs/disable/ value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40285" source="BID" patch="1">40285</ref>
      <ref url="http://drupal.org/node/803944" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/803944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58722" source="XF">chaos-tool-unspecified-csrf(58722)</ref>
      <ref url="http://www.madirish.net/?article=458" source="MISC">http://www.madirish.net/?article=458</ref>
      <ref url="http://secunia.com/advisories/39884" source="SECUNIA" adv="1">39884</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/May/272" source="FULLDISC">20100520 Drupal Chaos Tools Suite (Ctools) Module Multiple Vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angrydonuts" name="ctools">
        <vers num="6.x-1.0" edition="alpha1" />
        <vers num="6.x-1.0" edition="alpha2" />
        <vers num="6.x-1.0" edition="alpha3" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-1.0" edition="beta4" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1548" published="2010-05-21" name="CVE-2010-1548" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40285" source="BID" patch="1">40285</ref>
      <ref url="http://drupal.org/node/803944" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/803944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58724" source="XF">chaos-tool-permissions-sec-bypass(58724)</ref>
      <ref url="http://www.madirish.net/?article=458" source="MISC">http://www.madirish.net/?article=458</ref>
      <ref url="http://secunia.com/advisories/39884" source="SECUNIA" adv="1">39884</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/May/272" source="FULLDISC">20100520 Drupal Chaos Tools Suite (Ctools) Module Multiple Vulns</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angrydonuts" name="ctools">
        <vers num="6.x-1.0" edition="alpha1" />
        <vers num="6.x-1.0" edition="alpha2" />
        <vers num="6.x-1.0" edition="alpha3" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-1.0" edition="beta4" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1549" published="2010-05-07" name="CVE-2010-1549" modified="2010-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511146/100/0/threaded" source="HP">SSRT071328</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511146/100/0/threaded" source="HP">SSRT071328</ref>
      <ref url="http://seclists.org/bugtraq/2010/May/69" source="HP">HPSBMA02528</ref>
      <ref url="http://seclists.org/bugtraq/2010/May/69" source="HP">HPSBMA02528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="loadrunner">
        <vers num="7.0" />
        <vers num="7.02" />
        <vers num="7.5" />
        <vers num="7.51" />
        <vers num="7.6" />
        <vers num="7.8" />
        <vers num="8.0" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="9.0" />
        <vers prev="1" num="9.10" />
      </prod>
      <prod vendor="hp" name="performance_center">
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1550" published="2010-05-13" name="CVE-2010-1550" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in the sel parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" patch="1" adv="1">SSRT010098</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-081/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-081/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511245/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-081: HP OpenView NNM ovet_demandpoll sel CGI Variable Format String Remote Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1551" published="2010-05-13" name="CVE-2010-1551" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the sel parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-082/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-082/</ref>
      <ref url="http://www.securityfocus.com/bid/40067" source="BID">40067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511247/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-082: HP OpenView NNM netmon sel CGI Variable Remote Code Execution Vulnerability</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" adv="1">SSRT090226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1552" published="2010-05-13" name="CVE-2010-1552" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" patch="1" adv="1">SSRT090227</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-083/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-083/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511248/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-083: HP OpenView NNM snmpviewer.exe CGI Multiple Variable Remote Code Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/8157" source="SREASON">8157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1553" published="2010-05-13" name="CVE-2010-1553" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" patch="1" adv="1">SSRT010098</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-084/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-084/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511241/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-084: HP OpenView NNM getnnmdata.exe CGI Invalid MaxAge Remote Code Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/8153" source="SREASON">8153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1554" published="2010-05-13" name="CVE-2010-1554" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" patch="1" adv="1">SSRT010098</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-085/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-085/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511249/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-085: HP OpenView NNM getnnmdata.exe CGI Invalid ICount Remote Code Execution Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/14181" source="EXPLOIT-DB">14181</ref>
      <ref url="http://securityreason.com/securityalert/8154" source="SREASON">8154</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1555" published="2010-05-13" name="CVE-2010-1555" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127360750704351&amp;w=2" source="HP" patch="1" adv="1">SSRT090230</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-086/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-086/</ref>
      <ref url="http://www.securityfocus.com/bid/40072" source="BID">40072</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511250/100/0/threaded" source="BUGTRAQ">20100511 ZDI-10-086: HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1556" published="2010-05-14" name="CVE-2010-1556" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Systems Insight Manager (SIM) 5.3, 5.3 Update 1, and 6.0 allows remote attackers to obtain sensitive information and modify data via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40111" source="BID">40111</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127370451008940&amp;w=2" source="HP">HPSBMA02520</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127370451008940&amp;w=2" source="HP">HPSBMA02520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers num="5.3" edition="update_1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1557" published="2010-05-14" name="CVE-2010-1557" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HP Insight Control Server Migration before 6.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://osvdb.org/64615" source="OSVDB">64615</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127370362007932&amp;w=2" source="HP">SSRT100086</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127370362007932&amp;w=2" source="HP">SSRT100086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_control_server_migration_for_windows">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1558" published="2010-05-14" name="CVE-2010-1558" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58618" source="XF">hp-mfp-sendtoemail-unauth-access(58618)</ref>
      <ref url="http://www.securityfocus.com/bid/40147" source="BID">40147</ref>
      <ref url="http://osvdb.org/64661" source="OSVDB">64661</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127376308013422&amp;w=2" source="HP" adv="1">HPSBPI02532</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127376308013422&amp;w=2" source="HP" adv="1">HPSBPI02532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="multifunction_peripheral_digital_sending_software">
        <vers num="4.00" />
        <vers num="4.02" />
        <vers num="4.03" />
        <vers num="4.04" />
        <vers num="4.05" />
        <vers num="4.06" />
        <vers num="4.07" />
        <vers num="4.08" />
        <vers num="4.09" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.12" />
        <vers num="4.13" />
        <vers num="4.14" />
        <vers num="4.15" />
        <vers num="4.16" />
        <vers num="4.17" />
        <vers prev="1" num="4.18.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1559" published="2010-04-27" name="CVE-2010-1559" modified="2010-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39385" source="SECUNIA" adv="1">39385</ref>
      <ref url="http://joomlacode.org/gf/project/sermon_speaker/news/?action=NewsThreadView&amp;id=2549" source="CONFIRM">http://joomlacode.org/gf/project/sermon_speaker/news/?action=NewsThreadView&amp;id=2549</ref>
      <ref url="http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;forum_id=7897&amp;_forum_action=ForumMessageBrowse&amp;thread_id=15219" source="CONFIRM">http://joomlacode.org/gf/project/sermon_speaker/forum/?action=ForumBrowse&amp;forum_id=7897&amp;_forum_action=ForumMessageBrowse&amp;thread_id=15219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_hess" name="com_sermonspeaker">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1560" published="2010-04-27" name="CVE-2010-1560" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21426108" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg21426108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58070" source="XF">db2-repeat-dos(58070)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0982" source="VUPEN" adv="1">ADV-2010-0982</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC65922" source="AIXAPAR">IC65922</ref>
      <ref url="http://secunia.com/advisories/39500" source="SECUNIA" adv="1">39500</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14613" source="OVAL">oval:org.mitre.oval:def:14613</ref>
      <ref url="http://osvdb.org/64041" source="OSVDB">64041</ref>
      <ref url="http://attrition.org/pipermail/vim/2010-April/002341.html" source="VIM">20100423 IBM 'REPEAT' BoF advisory - APAR IC65922</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers prev="1" num="9.1" edition="fp1" />
        <vers prev="1" num="9.1" edition="fp2" />
        <vers prev="1" num="9.1" edition="fp3" />
        <vers prev="1" num="9.1" edition="fp3a" />
        <vers prev="1" num="9.1" edition="fp4" />
        <vers prev="1" num="9.1" edition="fp4a" />
        <vers prev="1" num="9.1" edition="fp5" />
        <vers prev="1" num="9.1" edition="fp6" />
        <vers prev="1" num="9.1" edition="fp6a" />
        <vers prev="1" num="9.1" edition="fp7" />
        <vers prev="1" num="9.1" edition="fp7a" />
        <vers prev="1" num="9.1" edition="fp8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1561" published="2010-05-14" name="CVE-2010-1561" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S11 and 9.7(3)P before 9.7(3)P11 allows remote attackers to cause a denial of service (device crash) via a long message, aka Bug ID CSCsk44115.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40123" source="BID">40123</ref>
      <ref url="http://osvdb.org/64685" source="OSVDB">64685</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)p" />
        <vers num="9.7(3)p9" />
        <vers num="9.7(3)s" />
        <vers num="9.7(3)s10" />
        <vers num="9.7(3)s9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1562" published="2010-05-14" name="CVE-2010-1562" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed Contact header, aka Bug ID CSCsj98521.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://osvdb.org/64684" source="OSVDB">64684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)p" />
        <vers num="9.7(3)s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1563" published="2010-05-14" name="CVE-2010-1563" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsk04588.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40125" source="BID">40125</ref>
      <ref url="http://osvdb.org/64683" source="OSVDB">64683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)p" />
        <vers num="9.7(3)s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1564" reject="1" published="2010-04-14" name="CVE-2010-1564" modified="2010-04-14">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1564.  Reason: This candidate is a duplicate of CVE-2009-1564.  A typo caused the wrong ID to be used.  Notes: All CVE users should reference CVE-2009-1564 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-1565" published="2010-05-14" name="CVE-2010-1565" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (TCP socket exhaustion) via unknown vectors, aka Bug ID CSCsk13561.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40128" source="BID">40128</ref>
      <ref url="http://osvdb.org/64682" source="OSVDB">64682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.7(3)p" />
        <vers num="9.7(3)s" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1567" published="2010-05-14" name="CVE-2010-1567" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.8(1)S5 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsz13590.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2c519.shtml" source="CISCO" patch="1" adv="1">20100512 Multiple Vulnerabilities in Cisco PGW Softswitch</ref>
      <ref url="http://www.securityfocus.com/bid/40126" source="BID">40126</ref>
      <ref url="http://osvdb.org/64681" source="OSVDB">64681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="pgw_2200_softswitch">
        <vers num="9.6(1)" />
        <vers num="9.7(3)" />
        <vers prev="1" num="9.8(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1568" published="2010-05-14" name="CVE-2010-1568" modified="2010-05-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intended to be encrypted, aka bug 65623.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a0080b2c505.html" source="CISCO" adv="1">20100511 Cisco IronPort Desktop Flag Plug-in for Outlook Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_desktop_flag_plugin_for_outlook">
        <vers num="6.2.4.3" />
        <vers prev="1" num="6.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1570" published="2010-06-09" name="CVE-2010-1570" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtml" source="CISCO" patch="1" adv="1">20100609 Vulnerabilities in Cisco Unified Contact Center Express</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59276" source="XF">cisco-unified-ccx-cti-dos(59276)</ref>
      <ref url="http://www.securitytracker.com/id?1024081" source="SECTRACK">1024081</ref>
      <ref url="http://www.securityfocus.com/bid/40684" source="BID">40684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="customer_response_solution">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="cisco" name="unified_contact_center_express">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="cisco" name="unified_ip_interactive_voice_response">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1571" published="2010-06-09" name="CVE-2010-1571" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtml" source="CISCO" patch="1" adv="1">20100609 Vulnerabilities in Cisco Unified Contact Center Express</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59277" source="XF">cisco-unified-bootstrap-dir-traversal(59277)</ref>
      <ref url="http://www.securitytracker.com/id?1024082" source="SECTRACK">1024082</ref>
      <ref url="http://www.securityfocus.com/bid/40680" source="BID">40680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="customer_response_solution">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="cisco" name="unified_contact_center_express">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
      <prod vendor="cisco" name="unified_ip_interactive_voice_response">
        <vers num="5.0" />
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1572" published="2010-06-09" name="CVE-2010-1572" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the tech support diagnostic shell in Cisco Application Extension Platform (AXP) 1.1 and 1.1.5 allows local users to obtain sensitive configuration information and gain administrator privileges via unspecified API calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3290b.shtml" source="CISCO" patch="1" adv="1">20100609 Cisco Application Extension Platform Privilege Escalation Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59271" source="XF">cisco-aep-shell-privilege-escalation(59271)</ref>
      <ref url="http://www.securityfocus.com/bid/40682" source="BID">40682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_extension_framework">
        <vers num="1.1" />
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1573" published="2010-06-09" name="CVE-2010-1573" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59286" source="XF">wap54g-debug-command-execution(59286)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1419" source="VUPEN">ADV-2010-1419</ref>
      <ref url="http://www.securityfocus.com/bid/40648" source="BID">40648</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511733/100/0/threaded" source="BUGTRAQ">20100608 IS-2010-002 - Linksys WAP54Gv3 Remote Debug Root Shell</ref>
      <ref url="http://www.icysilence.org/?p=268" source="MISC">http://www.icysilence.org/?p=268</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=20682" source="CONFIRM" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=20682</ref>
      <ref url="http://secunia.com/advisories/40103" source="SECUNIA">40103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="wap54gv3">
        <vers prev="1" num="3.04.03" />
        <vers num="3.05.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1574" published="2010-07-08" name="CVE-2010-1574" modified="2010-07-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuration or obtain potentially sensitive information via SNMP requests, aka Bug ID CSCtf25589.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/732671" source="CERT-VN">VU#732671</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/60145" source="XF">cisco-industrial-snmp-unauth-access(60145)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1754" source="VUPEN">ADV-2010-1754</ref>
      <ref url="http://www.securityfocus.com/bid/41436" source="BID">41436</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3891f.shtml" source="CISCO" adv="1">20100707 Hard-Coded SNMP Community Names in Cisco Industrial Ethernet 3000 Series Switches Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1024173" source="SECTRACK">1024173</ref>
      <ref url="http://secunia.com/advisories/40407" source="SECUNIA" adv="1">40407</ref>
      <ref url="http://osvdb.org/66120" source="OSVDB">66120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="industrial_ethernet_3000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.2(52)se" />
        <vers num="12.2(52)se1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1575" published="2010-07-06" name="CVE-2010-1575" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete client-supplied ClientCert-* headers, which might allow remote attackers to bypass authentication via crafted header data, as demonstrated by a ClientCert-Subject-CN header, aka Bug ID CSCsz04690.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/resources/advisory/20100702-1/" source="MISC">http://www.vsecurity.com/resources/advisory/20100702-1/</ref>
      <ref url="http://www.securityfocus.com/bid/41315" source="BID">41315</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512144/100/0/threaded" source="BUGTRAQ">20100702 VSR Advisory: Multiple Cisco CSS / ACE Client Certificate and HTTP Header Manipulation Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024167" source="SECTRACK">1024167</ref>
      <ref url="http://osvdb.org/66091" source="OSVDB">66091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="08.20.1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1576" published="2010-07-06" name="CVE-2010-1576" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Cisco Content Services Switch (CSS) 11500 with software before 8.20.4.02 and the Application Control Engine (ACE) 4710 with software before A2(3.0) do not properly handle use of LF, CR, and LFCR as alternatives to the standard CRLF sequence between HTTP headers, which allows remote attackers to bypass intended header insertions or conduct HTTP request smuggling attacks via crafted header data, as demonstrated by LF characters preceding ClientCert-Subject and ClientCert-Subject-CN headers, aka Bug ID CSCta04885.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vsecurity.com/resources/advisory/20100702-1/" source="MISC">http://www.vsecurity.com/resources/advisory/20100702-1/</ref>
      <ref url="http://www.securityfocus.com/bid/41315" source="BID">41315</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512144/100/0/threaded" source="BUGTRAQ">20100702 VSR Advisory: Multiple Cisco CSS / ACE Client Certificate and HTTP Header Manipulation Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024168" source="SECTRACK">1024168</ref>
      <ref url="http://securitytracker.com/id?1024167" source="SECTRACK">1024167</ref>
      <ref url="http://osvdb.org/66092" source="OSVDB">66092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="a1(2.0)" />
        <vers num="a1(8.0)" />
        <vers prev="1" num="a3(2.5)" />
      </prod>
      <prod vendor="cisco" name="content_services_switch_11500">
        <vers num="08.20.1.01" />
        <vers num="8.20.0.01" />
        <vers num="8.20.1.01" />
        <vers num="8.20.2.01" />
        <vers prev="1" num="8.20.3.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1577" published="2010-07-28" name="CVE-2010-1577" modified="2010-07-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3bd1c.shtml" source="CISCO" patch="1" adv="1">20100721 CDS Internet Streamer: Web Server Directory Traversal Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/60567" source="XF">cisco-cds-streamer-directory-traversal(60567)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1881" source="VUPEN" adv="1">ADV-2010-1881</ref>
      <ref url="http://www.securitytracker.com/id?1024234" source="SECTRACK">1024234</ref>
      <ref url="http://secunia.com/advisories/40701" source="SECUNIA" adv="1">40701</ref>
      <ref url="http://osvdb.org/66508" source="OSVDB">66508</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="content_delivery_system">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="internet_streamer">
        <vers num="2.2(1)" />
        <vers num="2.3(1)" />
        <vers num="2.3(3)" />
        <vers num="2.3(5)" />
        <vers num="2.3(7)" />
        <vers num="2.3(9)" />
        <vers num="2.4(1)" />
        <vers num="2.4(3)" />
        <vers num="2.4(5)" />
        <vers num="2.5(1)" />
        <vers num="2.5(3)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1578" published="2010-08-09" name="CVE-2010-1578" modified="2010-08-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc77567.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtml" source="CISCO" patch="1" adv="1">20100804 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/40842" source="SECUNIA" adv="1">40842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="7.2(1)" />
        <vers num="7.2(1.22)" />
        <vers num="7.2(2)" />
        <vers num="7.2(2.10)" />
        <vers num="7.2(2.14)" />
        <vers num="7.2(2.15)" />
        <vers num="7.2(2.16)" />
        <vers num="7.2(2.17)" />
        <vers num="7.2(2.19)" />
        <vers num="7.2(2.48)" />
        <vers num="7.2(2.5)" />
        <vers num="7.2(2.7)" />
        <vers num="7.2(2.8)" />
        <vers num="7.2(3)" />
        <vers num="7.2(4)" />
        <vers num="7.2(5)" />
        <vers num="8.0" />
        <vers num="8.0(2)" />
        <vers num="8.0(3)" />
        <vers num="8.0(4)" />
        <vers num="8.0(5)" />
        <vers num="8.1(1)" />
        <vers num="8.1(2)" />
        <vers num="8.2(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1579" published="2010-08-09" name="CVE-2010-1579" modified="2010-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc79922.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtml" source="CISCO" patch="1" adv="1">20100804 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/40842" source="SECUNIA" adv="1">40842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="7.2(1)" />
        <vers num="7.2(1.22)" />
        <vers num="7.2(2)" />
        <vers num="7.2(2.10)" />
        <vers num="7.2(2.14)" />
        <vers num="7.2(2.15)" />
        <vers num="7.2(2.16)" />
        <vers num="7.2(2.17)" />
        <vers num="7.2(2.19)" />
        <vers num="7.2(2.48)" />
        <vers num="7.2(2.5)" />
        <vers num="7.2(2.7)" />
        <vers num="7.2(2.8)" />
        <vers num="7.2(3)" />
        <vers num="7.2(4)" />
        <vers num="7.2(5)" />
        <vers num="8.0" />
        <vers num="8.0(2)" />
        <vers num="8.0(3)" />
        <vers num="8.0(4)" />
        <vers num="8.0(5)" />
        <vers num="8.1(1)" />
        <vers num="8.1(2)" />
        <vers num="8.2(1)" />
        <vers num="8.2(2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1580" published="2010-08-09" name="CVE-2010-1580" modified="2010-08-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SunRPC inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), and 8.2 before 8.2(2) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via crafted SunRPC UDP packets, aka Bug ID CSCtc85753.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtml" source="CISCO" patch="1" adv="1">20100804 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/40842" source="SECUNIA" adv="1">40842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="7.2(1)" />
        <vers num="7.2(1.22)" />
        <vers num="7.2(2)" />
        <vers num="7.2(2.10)" />
        <vers num="7.2(2.14)" />
        <vers num="7.2(2.15)" />
        <vers num="7.2(2.16)" />
        <vers num="7.2(2.17)" />
        <vers num="7.2(2.19)" />
        <vers num="7.2(2.48)" />
        <vers num="7.2(2.5)" />
        <vers num="7.2(2.7)" />
        <vers num="7.2(2.8)" />
        <vers num="7.2(3)" />
        <vers num="7.2(4)" />
        <vers num="7.2(5)" />
        <vers num="8.0" />
        <vers num="8.0(2)" />
        <vers num="8.0(3)" />
        <vers num="8.0(4)" />
        <vers num="8.0(5)" />
        <vers num="8.1(1)" />
        <vers num="8.1(2)" />
        <vers num="8.2(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1581" published="2010-08-09" name="CVE-2010-1581" modified="2010-08-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Transport Layer Security (TLS) implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 before 7.2(5), 8.0 before 8.0(5.15), 8.1 before 8.1(2.44), 8.2 before 8.2(2.17), and 8.3 before 8.3(1.6) and Cisco PIX Security Appliances 500 series devices allows remote attackers to cause a denial of service (device reload) via a sequence of crafted TLS packets, aka Bug ID CSCtd32627.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b3f12f.shtml" source="CISCO" patch="1" adv="1">20100804 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://www.securityfocus.com/bid/42187" source="BID">42187</ref>
      <ref url="http://secunia.com/advisories/40842" source="SECUNIA" adv="1">40842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="7.2(1)" />
        <vers num="7.2(1.22)" />
        <vers num="7.2(2)" />
        <vers num="7.2(2.10)" />
        <vers num="7.2(2.14)" />
        <vers num="7.2(2.15)" />
        <vers num="7.2(2.16)" />
        <vers num="7.2(2.17)" />
        <vers num="7.2(2.19)" />
        <vers num="7.2(2.48)" />
        <vers num="7.2(2.5)" />
        <vers num="7.2(2.7)" />
        <vers num="7.2(2.8)" />
        <vers num="7.2(3)" />
        <vers num="7.2(4)" />
        <vers num="7.2(5)" />
        <vers num="8.0" />
        <vers num="8.0(2)" />
        <vers num="8.0(3)" />
        <vers num="8.0(4)" />
        <vers num="8.0(5)" />
        <vers num="8.1(1)" />
        <vers num="8.1(2)" />
        <vers num="8.2" />
        <vers num="8.2(1)" />
        <vers num="8.2(2)" />
        <vers num="8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1583" published="2010-05-06" name="CVE-2010-1583" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58241" source="XF">taskfreak-loadbykey-sql-injection(58241)</ref>
      <ref url="http://www.taskfreak.com/versions.html" source="MISC">http://www.taskfreak.com/versions.html</ref>
      <ref url="http://www.securityfocus.com/bid/39793" source="BID">39793</ref>
      <ref url="http://www.madirish.net/?article=456" source="MISC">http://www.madirish.net/?article=456</ref>
      <ref url="http://www.exploit-db.com/exploits/12452" source="EXPLOIT-DB">12452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="taskfreak" name="taskfreak!">
        <vers num="0.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers prev="1" num="0.6.2" />
      </prod>
      <prod vendor="tirzen" name="tirzen_framework">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1584" published="2010-05-19" name="CVE-2010-1584" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/795118" source="CONFIRM" patch="1">http://drupal.org/node/795118</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58521" source="XF">context-adminblocks-xss(58521)</ref>
      <ref url="http://www.theregister.co.uk/2010/05/10/drupal_security_bug/" source="MISC">http://www.theregister.co.uk/2010/05/10/drupal_security_bug/</ref>
      <ref url="http://www.securityfocus.com/bid/40056" source="BID">40056</ref>
      <ref url="http://www.packetstormsecurity.com/1005-exploits/drupalab-xss.txt" source="MISC">http://www.packetstormsecurity.com/1005-exploits/drupalab-xss.txt</ref>
      <ref url="http://www.madirish.net/?article=457" source="MISC">http://www.madirish.net/?article=457</ref>
      <ref url="http://drupal.org/node/794718" source="CONFIRM">http://drupal.org/node/794718</ref>
      <ref url="http://drupal.org/cvs?commit=365210" source="CONFIRM">http://drupal.org/cvs?commit=365210</ref>
      <ref url="http://crackingdrupal.com/blog/greggles/mitigation-against-cve-2010-1584-drupal-context-module-xss" source="MISC">http://crackingdrupal.com/blog/greggles/mitigation-against-cve-2010-1584-drupal-context-module-xss</ref>
    </refs>
    <vuln_soft>
      <prod vendor="steven_jones" name="context">
        <vers prev="1" num="6.x-2.0" edition="alpha1" />
        <vers prev="1" num="6.x-2.0" edition="alpha2" />
        <vers prev="1" num="6.x-2.0" edition="beta1" />
        <vers prev="1" num="6.x-2.0" edition="beta2" />
        <vers prev="1" num="6.x-2.0" edition="beta3" />
        <vers prev="1" num="6.x-2.0" edition="beta4" />
        <vers prev="1" num="6.x-2.0" edition="beta5" />
        <vers prev="1" num="6.x-2.0" edition="beta6" />
        <vers prev="1" num="6.x-2.0" edition="beta7" />
        <vers prev="1" num="6.x-2.0" edition="rc1" />
        <vers prev="1" num="6.x-2.0" edition="rc2" />
        <vers prev="1" num="6.x-2.0" edition="rc3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1585" published="2010-04-28" name="CVE-2010-1585" modified="2011-08-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=562547" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=562547</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510883/100/0/threaded" source="BUGTRAQ">20100421 Security-Assessment.com WhitePaper/Addendum: Cross Context Scripting with Firefox &amp; Exploiting Cross Context Scripting vulnerabilities in Firefox</ref>
      <ref url="http://www.security-assessment.com/files/whitepapers/Cross_Context_Scripting_with_Firefox.pdf" source="MISC">http://www.security-assessment.com/files/whitepapers/Cross_Context_Scripting_with_Firefox.pdf</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-08.html" source="CONFIRM">http://www.mozilla.org/security/announce/2011/mfsa2011-08.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" source="MANDRIVA">MDVSA-2011:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/" source="MISC">http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12532" source="OVAL">oval:org.mitre.oval:def:12532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.10" />
        <vers num="3.5.11" />
        <vers num="3.5.12" />
        <vers num="3.5.13" />
        <vers num="3.5.14" />
        <vers num="3.5.15" />
        <vers prev="1" num="3.5.16" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.5.8" />
        <vers num="3.5.9" />
        <vers num="3.6" />
        <vers num="3.6.10" />
        <vers num="3.6.11" />
        <vers num="3.6.12" />
        <vers num="3.6.13" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.6" />
        <vers num="3.6.7" />
        <vers num="3.6.8" />
        <vers num="3.6.9" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="alpha_1" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers prev="1" num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.7.1" />
        <vers num="1.7.3" />
        <vers num="2.0" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.22" />
        <vers num="2.0.0.23" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers prev="1" num="3.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1586" published="2010-04-28" name="CVE-2010-1586" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://yehg.net/lab/pr0js/advisories/hp_system_management_homepage_url_redirection_abuse" source="MISC">http://yehg.net/lab/pr0js/advisories/hp_system_management_homepage_url_redirection_abuse</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58107" source="XF">hp-smh-redirecturl-phishing(58107)</ref>
      <ref url="http://www.securityfocus.com/bid/39676" source="BID">39676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1" />
        <vers num="2.1.0-103" />
        <vers num="2.1.0-103(a)" />
        <vers num="2.1.0-109" />
        <vers num="2.1.0-118" />
        <vers num="2.1.1" />
        <vers num="2.1.10-186" />
        <vers num="2.1.11-197" />
        <vers num="2.1.12-118" />
        <vers num="2.1.12-200" />
        <vers num="2.1.2" />
        <vers num="2.1.2-127" />
        <vers num="2.1.3" />
        <vers num="2.1.3.132" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.5-146" />
        <vers num="2.1.6" />
        <vers num="2.1.6-156" />
        <vers num="2.1.7" />
        <vers num="2.1.7-168" />
        <vers num="2.1.8" />
        <vers num="2.1.8-177" />
        <vers num="2.1.9" />
        <vers num="2.1.9-178" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1587" published="2010-04-28" name="CVE-2010-1587" modified="2010-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.apache.org/activemq/browse/AMQ-2700" source="CONFIRM" patch="1">https://issues.apache.org/activemq/browse/AMQ-2700</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0979" source="VUPEN" adv="1">ADV-2010-0979</ref>
      <ref url="http://www.securityfocus.com/bid/39636" source="BID">39636</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510896/100/0/threaded" source="BUGTRAQ">20100422 Apache ActiveMQ is prone to source code disclosure vulnerability.</ref>
      <ref url="http://www.osvdb.org/64020" source="OSVDB">64020</ref>
      <ref url="http://secunia.com/advisories/39567" source="SECUNIA" adv="1">39567</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0278.html" source="FULLDISC">20100422 Apache ActiveMQ is prone to source code disclosure vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="activemq">
        <vers num="5.0.0" />
        <vers num="5.1.0" />
        <vers num="5.2.0" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.4-snapshot" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1588" published="2010-04-28" name="CVE-2010-1588" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Getwebsess function in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via the websess parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55821" source="XF">shoppingcart-websess-sql-injection(55821)</ref>
      <ref url="http://secunia.com/advisories/38283" source="SECUNIA" adv="1">38283</ref>
      <ref url="http://osvdb.org/61890" source="OSVDB">61890</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0400.html" source="FULLDISC">20100120 Insufficient User Input Validation in VP-ASP 6.50 Demo Code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vpasp" name="vp-asp_shopping_cart">
        <vers num="5.50" />
        <vers num="6.00" />
        <vers prev="1" num="6.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1589" published="2010-04-28" name="CVE-2010-1589" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55824" source="XF">shoppingcart-remotehost-dir-traversal(55824)</ref>
      <ref url="http://secunia.com/advisories/38283" source="SECUNIA" adv="1">38283</ref>
      <ref url="http://osvdb.org/61891" source="OSVDB">61891</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0400.html" source="FULLDISC">20100120 Insufficient User Input Validation in VP-ASP 6.50 Demo Code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vpasp" name="vp-asp_shopping_cart">
        <vers num="5.50" />
        <vers num="6.00" />
        <vers prev="1" num="6.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1590" published="2010-04-28" name="CVE-2010-1590" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to inject arbitrary web script or HTML via the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0400.html" source="FULLDISC">20100120 Insufficient User Input Validation in VP-ASP 6.50 Demo Code</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vpasp" name="vp-asp_shopping_cart">
        <vers num="5.50" />
        <vers num="6.00" />
        <vers prev="1" num="6.50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1591" published="2010-04-28" name="CVE-2010-1591" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55869" source="XF">rising-antivirus-drivers-priv-escalation(55869)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0218" source="VUPEN" adv="1">ADV-2010-0218</ref>
      <ref url="http://www.securityfocus.com/bid/37951" source="BID">37951</ref>
      <ref url="http://www.ntinternals.org/ntiadv0902/ntiadv0902.html" source="MISC">http://www.ntinternals.org/ntiadv0902/ntiadv0902.html</ref>
      <ref url="http://www.ntinternals.org/ntiadv0805/ntiadv0805.html" source="MISC">http://www.ntinternals.org/ntiadv0805/ntiadv0805.html</ref>
      <ref url="http://secunia.com/advisories/38335" source="SECUNIA" adv="1">38335</ref>
      <ref url="http://osvdb.org/61946" source="OSVDB">61946</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rising-global" name="rising_antivirus">
        <vers num="2008" />
        <vers num="2009" />
        <vers num="2010" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1592" published="2010-04-28" name="CVE-2010-1592" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">sandra.sys 15.18.1.1 and earlier in the Sandra Device Driver in SiSoftware Sandra 16.10.2010.1 and earlier allows local users to gain privileges or cause a denial of service (system crash) via unspecified vectors involving "Model-Specific Registers."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0223" source="VUPEN" adv="1">ADV-2010-0223</ref>
      <ref url="http://www.ntinternals.org/ntiadv0808/ntiadv0808.html" source="MISC">http://www.ntinternals.org/ntiadv0808/ntiadv0808.html</ref>
      <ref url="http://secunia.com/advisories/38212" source="SECUNIA" adv="1">38212</ref>
      <ref url="http://osvdb.org/61947" source="OSVDB">61947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sisoftware" name="sandra">
        <vers prev="1" num="16.10.2010.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1593" published="2010-04-28" name="CVE-2010-1593" modified="2010-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.silverstripe.org/security-releases/" source="CONFIRM" patch="1" adv="1">http://www.silverstripe.org/security-releases/</ref>
      <ref url="http://www.securityfocus.com/bid/37923" source="BID" patch="1">37923</ref>
      <ref url="http://open.silverstripe.org/changeset/97074" source="CONFIRM" patch="1">http://open.silverstripe.org/changeset/97074</ref>
      <ref url="http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456" source="CONFIRM" patch="1">http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55839" source="XF">silverstripe-search-xss(55839)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55838" source="XF">silverstripe-comment-xss(55838)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509139/100/0/threaded" source="BUGTRAQ">20100122 Silverstripe &lt;= v2.3.4: two XSS vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/38347" source="SECUNIA" adv="1">38347</ref>
      <ref url="http://secunia.com/advisories/38290" source="SECUNIA" adv="1">38290</ref>
      <ref url="http://osvdb.org/61923" source="OSVDB">61923</ref>
      <ref url="http://osvdb.org/61921" source="OSVDB">61921</ref>
      <ref url="http://open.silverstripe.org/wiki/ChangeLog/2.3.5" source="CONFIRM">http://open.silverstripe.org/wiki/ChangeLog/2.3.5</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.html" source="FULLDISC">20100122 Silverstripe &lt;= v2.3.4: two XSS vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silverstripe" name="silverstripe">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.4" />
        <vers num="2.3.0" edition="rc1" />
        <vers num="2.3.0" edition="rc2" />
        <vers num="2.3.0" edition="rc3" />
        <vers num="2.3.1" edition="rc1" />
        <vers num="2.3.1" edition="rc2" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers prev="1" num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1594" published="2010-04-28" name="CVE-2010-1594" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to inject arbitrary web script or HTML via (1) the query string, (2) the BASE parameter, or (3) the ega_1 parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55874" source="XF">ocsinventoryng-index-xss(55874)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:178" source="MANDRIVA">MDVSA-2010:178</ref>
      <ref url="http://secunia.com/advisories/38311" source="SECUNIA" adv="1">38311</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txt</ref>
      <ref url="http://osvdb.org/61943" source="OSVDB">61943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.02.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1595" published="2010-04-28" name="CVE-2010-1595" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55872" source="XF">ocsinventoryng-index-sql-injection(55872)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:178" source="MANDRIVA">MDVSA-2010:178</ref>
      <ref url="http://secunia.com/advisories/38311" source="SECUNIA" adv="1">38311</ref>
      <ref url="http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1001-exploits/ocsinventoryng-sqlxss.txt</ref>
      <ref url="http://osvdb.org/61942" source="OSVDB">61942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.02.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1596" published="2010-04-28" name="CVE-2010-1596" modified="2012-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sitracker.org/wiki/ReleaseNotes351" source="CONFIRM" patch="1">http://sitracker.org/wiki/ReleaseNotes351</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55871" source="XF">supportincident-ldap-security-bypass(55871)</ref>
      <ref url="http://www.securityfocus.com/bid/37949" source="BID">37949</ref>
      <ref url="http://sitracker.org/forum/viewtopic.php?f=4&amp;t=1416979&amp;p=2292" source="CONFIRM">http://sitracker.org/forum/viewtopic.php?f=4&amp;t=1416979&amp;p=2292</ref>
      <ref url="http://secunia.com/advisories/38329" source="SECUNIA" adv="1">38329</ref>
      <ref url="http://osvdb.org/61945" source="OSVDB">61945</ref>
      <ref url="http://bugs.sitracker.org/view.php?id=1047" source="CONFIRM">http://bugs.sitracker.org/view.php?id=1047</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitracker" name="support_incident_tracker">
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.22pl1" />
        <vers num="3.23" />
        <vers num="3.24" edition="beta-2" />
        <vers num="3.30" edition="beta2" />
        <vers num="3.31" />
        <vers num="3.32" />
        <vers num="3.33" />
        <vers num="3.35" edition="beta1" />
        <vers num="3.36" />
        <vers num="3.40" edition="beta1" />
        <vers num="3.41" />
        <vers num="3.45" edition="beta1" />
        <vers prev="1" num="3.50" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1597" published="2010-04-29" name="CVE-2010-1597" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in zgtips.dll in ZipGenius 6.3.1.2552 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing an entry with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58022" source="XF">zipgenius-zgtips-bo(58022)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0966" source="VUPEN" adv="1">ADV-2010-0966</ref>
      <ref url="http://www.securityfocus.com/bid/39622" source="BID">39622</ref>
      <ref url="http://www.exploit-db.com/exploits/12326" source="EXPLOIT-DB">12326</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-029-zipgenius-v6-3-1-2552-zgtips-dll-stack-buffer-overflow/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-029-zipgenius-v6-3-1-2552-zgtips-dll-stack-buffer-overflow/</ref>
      <ref url="http://www.corelan.be:8800/advisories.php?id=CORELAN-10-029" source="MISC">http://www.corelan.be:8800/advisories.php?id=CORELAN-10-029</ref>
      <ref url="http://secunia.com/advisories/39497" source="SECUNIA" adv="1">39497</ref>
      <ref url="http://osvdb.org/63971" source="OSVDB">63971</ref>
      <ref url="http://feeds.feedburner.com/zipgeniusnews" source="CONFIRM">http://feeds.feedburner.com/zipgeniusnews</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zipgenius" name="zipgenius">
        <vers num="6.3.1.2552" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1598" published="2010-04-29" name="CVE-2010-1598" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">phpThumb.php in phpThumb() 1.7.9 and possibly other versions, when ImageMagick is installed, allows remote attackers to execute arbitrary commands via the fltr[] parameter, as discovered in the wild in April 2010.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58040" source="XF">phpthumb-phpthumb-command-execution(58040)</ref>
      <ref url="http://www.securityfocus.com/bid/39605" source="BID">39605</ref>
      <ref url="http://secunia.com/advisories/39556" source="SECUNIA" adv="1">39556</ref>
      <ref url="http://osvdb.org/63939" source="OSVDB">63939</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silisoftware" name="phpthumb()">
        <vers num="1.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1599" published="2010-04-29" name="CVE-2010-1599" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58082" source="XF">nkinfoweb-loadorder-sql-injection(58082)</ref>
      <ref url="http://www.exploit-db.com/exploits/12354" source="EXPLOIT-DB">12354</ref>
      <ref url="http://secunia.com/advisories/39609" source="SECUNIA" adv="1">39609</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/nkinfoweb-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/nkinfoweb-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nkinfoweb" name="nkinfoweb">
        <vers num="2.5" />
        <vers num="5.2.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1600" published="2010-04-29" name="CVE-2010-1600" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57906" source="XF">mediamall-category-sql-injection(57906)</ref>
      <ref url="http://www.thefactory.ro/shop/joomla-components/media-mall.html" source="CONFIRM">http://www.thefactory.ro/shop/joomla-components/media-mall.html</ref>
      <ref url="http://www.securityfocus.com/bid/39488" source="BID">39488</ref>
      <ref url="http://www.packetstormsecurity.com/1004-exploits/joomlamediamallfactory-bsql.txt" source="MISC">http://www.packetstormsecurity.com/1004-exploits/joomlamediamallfactory-bsql.txt</ref>
      <ref url="http://www.osvdb.org/63940" source="OSVDB">63940</ref>
      <ref url="http://www.exploit-db.com/exploits/12234" source="EXPLOIT-DB">12234</ref>
      <ref url="http://secunia.com/advisories/39546" source="SECUNIA" adv="1">39546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thefactory" name="com_mediamall">
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1601" published="2010-04-29" name="CVE-2010-1601" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JA Comment (com_jacomment) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57848" source="XF">comjacomment-index-file-inlclude(57848)</ref>
      <ref url="http://www.securityfocus.com/bid/39516" source="BID">39516</ref>
      <ref url="http://www.osvdb.org/63802" source="OSVDB">63802</ref>
      <ref url="http://www.exploit-db.com/exploits/12236" source="EXPLOIT-DB">12236</ref>
      <ref url="http://secunia.com/advisories/39472" source="SECUNIA" adv="1">39472</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajacomment-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajacomment-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlamart" name="com_jacomment">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1602" published="2010-04-29" name="CVE-2010-1602" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0932" source="VUPEN" adv="1">ADV-2010-0932</ref>
      <ref url="http://www.securityfocus.com/bid/39548" source="BID">39548</ref>
      <ref url="http://www.exploit-db.com/exploits/12283" source="EXPLOIT-DB">12283</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlazimbcomment-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlazimbcomment-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zimbllc" name="com_zimbcomment">
        <vers num="0.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1603" published="2010-04-29" name="CVE-2010-1603" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the ZiMB Core (aka ZiMBCore or com_zimbcore) component 0.1 in the ZiMB Manager collection for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0931" source="VUPEN" adv="1">ADV-2010-0931</ref>
      <ref url="http://www.securityfocus.com/bid/39546" source="BID">39546</ref>
      <ref url="http://www.exploit-db.com/exploits/12284" source="EXPLOIT-DB">12284</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlazimbmanager-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlazimbmanager-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zimbllc" name="com_zimbcore">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1604" published="2010-04-29" name="CVE-2010-1604" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) user parameter (aka login field) and (2) passwd parameter (aka password field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58080" source="XF">portalscript-adminlogin-sql-injection(58080)</ref>
      <ref url="http://www.exploit-db.com/exploits/12370" source="EXPLOIT-DB">12370</ref>
      <ref url="http://secunia.com/advisories/39601" source="SECUNIA" adv="1">39601</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncrypted" name="nct_jobs_portal_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1605" published="2010-04-29" name="CVE-2010-1605" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in isearch.php in NCT Jobs Portal Script allow remote attackers to execute arbitrary SQL commands via the (1) anyword and (2) cityname parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58079" source="XF">portalscript-isearch-sql-injection(58079)</ref>
      <ref url="http://secunia.com/advisories/39601" source="SECUNIA" adv="1">39601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncrypted" name="nct_jobs_portal_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1606" published="2010-04-29" name="CVE-2010-1606" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in NCT Jobs Portal Script allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) Keywords, (3) Tags, or (4) Desired City field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58081" source="XF">portalscript-search-xss(58081)</ref>
      <ref url="http://www.exploit-db.com/exploits/12370" source="EXPLOIT-DB">12370</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/nctjobsportal-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ncrypted" name="nct_jobs_portal_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1607" published="2010-04-29" name="CVE-2010-1607" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58032" source="XF">webmoney-index-file-inlcude(58032)</ref>
      <ref url="http://www.securityfocus.com/bid/39608" source="BID">39608</ref>
      <ref url="http://www.exploit-db.com/exploits/12316" source="EXPLOIT-DB">12316</ref>
      <ref url="http://secunia.com/advisories/39539" source="SECUNIA" adv="1">39539</ref>
      <ref url="http://osvdb.org/63979" source="OSVDB">63979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paysyspro" name="com_wmi">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1608" published="2010-04-29" name="CVE-2010-1608" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0.  NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/" source="MISC">https://forum.immunityinc.com/board/thread/1161/vulndisco-9-0/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58322" source="XF">lotusnotes-unspec-bo(58322)</ref>
      <ref url="http://www.securityfocus.com/bid/38300" source="BID">38300</ref>
      <ref url="http://secunia.com/advisories/38622" source="SECUNIA" adv="1">38622</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14489" source="OVAL">oval:org.mitre.oval:def:14489</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="8.5" />
        <vers num="8.5.1" />
        <vers num="8.5.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1609" published="2010-04-29" name="CVE-2010-1609" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SAP NetWeaver 2004 before SP21 and 2004s before SP13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0397" source="VUPEN" patch="1" adv="1">ADV-2010-0397</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509499/100/0/threaded" source="BUGTRAQ">20100211 [Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection</ref>
      <ref url="http://secunia.com/advisories/38629" source="SECUNIA" adv="1">38629</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0216.html" source="FULLDISC">20100211 [Onapsis Security Advisory 2010-003] SAP WebDynpro Runtime XSS/CSS Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sap" name="netweaver">
        <vers num="4.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1610" published="2010-04-29" name="CVE-2010-1610" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application administrator for requests that create an administrative account via a POST request with the route parameter set to "user/user/insert." NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/56061" source="XF">opencart-admin-csrf(56061)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509313/100/0/threaded" source="BUGTRAQ">20100202 OpenCart CSRF Vulnerability</ref>
      <ref url="http://secunia.com/advisories/38419" source="SECUNIA" adv="1">38419</ref>
      <ref url="http://forum.opencart.com/viewtopic.php?f=16&amp;t=10203&amp;p=49654&amp;hilit=csrf#p49654" source="CONFIRM">http://forum.opencart.com/viewtopic.php?f=16&amp;t=10203&amp;p=49654&amp;hilit=csrf#p49654</ref>
      <ref url="http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/" source="MISC">http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opencart" name="opencart">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1611" published="2010-04-29" name="CVE-2010-1611" modified="2010-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication of the administrator for requests that reset the administrator password via a POST to admin/ with an update action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://forum.alegrocart.com/viewtopic.php?f=8&amp;t=54" source="CONFIRM" patch="1" adv="1">http://forum.alegrocart.com/viewtopic.php?f=8&amp;t=54</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56037" source="XF">alegrocart-admin-csrf(56037)</ref>
      <ref url="http://secunia.com/advisories/38386" source="SECUNIA" adv="1">38386</ref>
      <ref url="http://packetstormsecurity.org/1002-exploits/alegrocart-xsrf.txt" source="MISC">http://packetstormsecurity.org/1002-exploits/alegrocart-xsrf.txt</ref>
      <ref url="http://osvdb.org/62073" source="OSVDB">62073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alegrocart" name="alegrocart">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1612" published="2010-04-29" name="CVE-2010-1612" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24024774" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024774</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24024773" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024773</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24024772" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024772</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24024771" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024771</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24024770" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg24024770</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IC61364" source="AIXAPAR" patch="1" adv="1">IC61364</ref>
      <ref url="http://www.securityfocus.com/bid/37952" source="BID">37952</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509163/100/0/threaded" source="BUGTRAQ">20100126 [IBM Datapower XS40] Denial of Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_datapower_b2b_appliance_xb60">
        <vers num="3.7.3.1" />
        <vers prev="1" num="3.7.3.10" />
        <vers num="3.7.3.2" />
        <vers num="3.7.3.3" />
        <vers num="3.7.3.4" />
        <vers num="3.7.3.5" />
        <vers num="3.7.3.6" />
        <vers num="3.7.3.7" />
        <vers num="3.7.3.8" />
        <vers num="3.7.3.9" />
        <vers num="3.8.0.0" />
        <vers num="3.8.0.1" />
        <vers num="3.8.0.2" />
        <vers num="3.8.0.3" />
        <vers num="3.8.0.4" />
      </prod>
      <prod vendor="ibm" name="websphere_datapower_datapower_integration_appliance_xi50">
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.3.1" />
        <vers prev="1" num="3.7.3.10" />
        <vers num="3.7.3.2" />
        <vers num="3.7.3.3" />
        <vers num="3.7.3.4" />
        <vers num="3.7.3.5" />
        <vers num="3.7.3.6" />
        <vers num="3.7.3.7" />
        <vers num="3.7.3.8" />
        <vers num="3.7.3.9" />
        <vers num="3.8.0.0" />
        <vers num="3.8.0.1" />
        <vers num="3.8.0.2" />
        <vers num="3.8.0.4" />
        <vers num="3.8.03" />
      </prod>
      <prod vendor="ibm" name="websphere_datapower_low_latency_appliance_xm70">
        <vers num="3.7.3.1" />
        <vers prev="1" num="3.7.3.10" />
        <vers num="3.7.3.2" />
        <vers num="3.7.3.3" />
        <vers num="3.7.3.4" />
        <vers num="3.7.3.5" />
        <vers num="3.7.3.6" />
        <vers num="3.7.3.7" />
        <vers num="3.7.3.8" />
        <vers num="3.7.3.9" />
        <vers num="3.8.0.0" />
        <vers num="3.8.0.1" />
        <vers num="3.8.0.2" />
        <vers num="3.8.0.3" />
        <vers num="3.8.0.4" />
      </prod>
      <prod vendor="ibm" name="websphere_datapower_xml_accelerator_xa35">
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.3.1" />
        <vers prev="1" num="3.7.3.10" />
        <vers num="3.7.3.2" />
        <vers num="3.7.3.3" />
        <vers num="3.7.3.4" />
        <vers num="3.7.3.5" />
        <vers num="3.7.3.6" />
        <vers num="3.7.3.7" />
        <vers num="3.7.3.8" />
        <vers num="3.7.3.9" />
        <vers num="3.8.0.0" />
        <vers num="3.8.0.1" />
        <vers num="3.8.0.2" />
        <vers num="3.8.0.3" />
        <vers num="3.8.0.4" />
      </prod>
      <prod vendor="ibm" name="websphere_datapower_xml_security_gateway_xs40">
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.3.1" />
        <vers prev="1" num="3.7.3.10" />
        <vers num="3.7.3.2" />
        <vers num="3.7.3.3" />
        <vers num="3.7.3.4" />
        <vers num="3.7.3.5" />
        <vers num="3.7.3.6" />
        <vers num="3.7.3.7" />
        <vers num="3.7.3.8" />
        <vers num="3.7.3.9" />
        <vers num="3.8.0.0" />
        <vers num="3.8.0.1" />
        <vers num="3.8.0.2" />
        <vers num="3.8.0.3" />
        <vers num="3.8.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1613" published="2010-04-29" name="CVE-2010-1613" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1614" published="2010-04-29" name="CVE-2010-1614" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the Login-As feature or (2) when the global search feature is enabled, unspecified global search forms in the Global Search Engine.  NOTE: vector 1 might be resultant from a cross-site request forgery (CSRF) vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1615" published="2010-04-29" name="CVE-2010-1615" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms elements" related to lib/form/selectgroups.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://cvs.moodle.org/moodle/mod/wiki/view.php?r1=1.76.2.6&amp;r2=1.76.2.7" source="CONFIRM">http://cvs.moodle.org/moodle/mod/wiki/view.php?r1=1.76.2.6&amp;r2=1.76.2.7</ref>
      <ref url="http://cvs.moodle.org/moodle/lib/form/selectgroups.php?r1=1.2.4.2&amp;r2=1.2.4.3" source="CONFIRM">http://cvs.moodle.org/moodle/lib/form/selectgroups.php?r1=1.2.4.2&amp;r2=1.2.4.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1616" published="2010-04-29" name="CVE-2010-1616" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://tracker.moodle.org/browse/MDL-16658" source="MISC">http://tracker.moodle.org/browse/MDL-16658</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1617" published="2010-04-29" name="CVE-2010-1617" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&amp;r2=1.168.2.29" source="CONFIRM">http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&amp;r2=1.168.2.29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1618" published="2010-04-29" name="CVE-2010-1618" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the phpCAS client library before 1.1.0, as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.ja-sig.org/wiki/display/CASC/phpCAS+ChangeLog" source="CONFIRM">http://www.ja-sig.org/wiki/display/CASC/phpCAS+ChangeLog</ref>
      <ref url="http://www.ja-sig.org/issues/browse/PHPCAS-52" source="CONFIRM" adv="1">http://www.ja-sig.org/issues/browse/PHPCAS-52</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ja-sig" name="phpcas_client_library">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
      </prod>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1619" published="2010-04-29" name="CVE-2010-1619" modified="2010-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or HTML via crafted HTML entities.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.10" />
        <vers num="1.8.11" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.8.9" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
        <vers num="1.9.5" />
        <vers num="1.9.6" />
        <vers num="1.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1620" published="2010-05-12" name="CVE-2010-1620" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to execute arbitrary code via a (1) file or (2) socket that provides configuration data with many entries, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://ftpmain.gnustep.org/pub/gnustep/core/gnustep-base-1.20.0.tar.gz" source="CONFIRM" patch="1">http://ftpmain.gnustep.org/pub/gnustep/core/gnustep-base-1.20.0.tar.gz</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/gnustep-base/+bug/573108" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/gnustep-base/+bug/573108</ref>
      <ref url="http://thread.gmane.org/gmane.comp.lib.gnustep.bugs/12336" source="CONFIRM">http://thread.gmane.org/gmane.comp.lib.gnustep.bugs/12336</ref>
      <ref url="http://secunia.com/advisories/39746" source="SECUNIA" adv="1">39746</ref>
      <ref url="http://savannah.gnu.org/bugs/?29755" source="CONFIRM">http://savannah.gnu.org/bugs/?29755</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127325778527537&amp;w=2" source="MLIST">[oss-security] 20100507 Re: CVE Assignment (gnustep)</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127324274005709&amp;w=2" source="MLIST">[oss-security] 20100507 Re: CVE Assignment (gnustep)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnustep" name="gnustep_base">
        <vers num="1.11.2" />
        <vers num="1.12.0" />
        <vers num="1.13.0" />
        <vers num="1.14.0" />
        <vers num="1.15.0" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.4" />
        <vers num="1.17.0" />
        <vers num="1.18.0" />
        <vers num="1.19.0" />
        <vers num="1.19.1" />
        <vers num="1.19.2" />
        <vers prev="1" num="1.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1621" published="2010-05-14" name="CVE-2010-1621" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39543" source="BID">39543</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:093" source="MANDRIVA">MDVSA-2010:093</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-46.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-46.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=51770" source="CONFIRM">http://bugs.mysql.com/bug.php?id=51770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers prev="1" num="5.1.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1622" published="2010-06-21" name="CVE-2010-1622" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0237" source="VUPEN">ADV-2011-0237</ref>
      <ref url="http://www.springsource.com/security/cve-2010-1622" source="CONFIRM" adv="1">http://www.springsource.com/security/cve-2010-1622</ref>
      <ref url="http://www.securityfocus.com/bid/40954" source="BID">40954</ref>
      <ref url="http://www.securityfocus.com/archive/1/511877" source="BUGTRAQ">20100618 CVE-2010-1622: Spring Framework execution of arbitrary code</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0175.html" source="REDHAT">RHSA-2011:0175</ref>
      <ref url="http://www.exploit-db.com/exploits/13918" source="EXPLOIT-DB">13918</ref>
      <ref url="http://secunia.com/advisories/43087" source="SECUNIA">43087</ref>
      <ref url="http://secunia.com/advisories/41025" source="SECUNIA">41025</ref>
      <ref url="http://secunia.com/advisories/41016" source="SECUNIA">41016</ref>
      <ref url="http://geronimo.apache.org/22x-security-report.html" source="CONFIRM">http://geronimo.apache.org/22x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html" source="CONFIRM">http://geronimo.apache.org/21x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html" source="CONFIRM">http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="springsource" name="spring_framework">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1623" published="2010-10-04" name="CVE-2010-1623" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/2556" source="VUPEN" patch="1" adv="1">ADV-2010-2556</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1003626" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1003626</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1003495" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1003495</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1003494" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1003494</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1003493" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1003493</ref>
      <ref url="http://svn.apache.org/viewvc?view=revision&amp;revision=1003492" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?view=revision&amp;revision=1003492</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0358" source="VUPEN" adv="1">ADV-2011-0358</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3074" source="VUPEN" adv="1">ADV-2010-3074</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3065" source="VUPEN" adv="1">ADV-2010-3065</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3064" source="VUPEN" adv="1">ADV-2010-3064</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2806" source="VUPEN" adv="1">ADV-2010-2806</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2557" source="VUPEN" adv="1">ADV-2010-2557</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1022-1" source="UBUNTU">USN-1022-1</ref>
      <ref url="http://www.securityfocus.com/bid/43673" source="BID">43673</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0897.html" source="REDHAT" adv="1">RHSA-2011:0897</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0896.html" source="REDHAT" adv="1">RHSA-2011:0896</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0950.html" source="REDHAT" adv="1">RHSA-2010:0950</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:192" source="MANDRIVA">MDVSA-2010:192</ref>
      <ref url="http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3" source="CONFIRM">http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601" source="AIXAPAR">PM31601</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601" source="AIXAPAR">PM31601</ref>
      <ref url="http://ubuntu.com/usn/usn-1021-1" source="UBUNTU">USN-1021-1</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.627828" source="SLACKWARE">SSA:2011-041-01</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1623" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1623</ref>
      <ref url="http://secunia.com/advisories/43285" source="SECUNIA" adv="1">43285</ref>
      <ref url="http://secunia.com/advisories/43211" source="SECUNIA" adv="1">43211</ref>
      <ref url="http://secunia.com/advisories/42537" source="SECUNIA" adv="1">42537</ref>
      <ref url="http://secunia.com/advisories/42403" source="SECUNIA" adv="1">42403</ref>
      <ref url="http://secunia.com/advisories/42367" source="SECUNIA" adv="1">42367</ref>
      <ref url="http://secunia.com/advisories/42361" source="SECUNIA" adv="1">42361</ref>
      <ref url="http://secunia.com/advisories/42015" source="SECUNIA" adv="1">42015</ref>
      <ref url="http://secunia.com/advisories/41701" source="SECUNIA" adv="1">41701</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12800" source="OVAL">oval:org.mitre.oval:def:12800</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html" source="SUSE">SUSE-SU-2011:1229</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.html" source="FEDORA">FEDORA-2010-15916</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.html" source="FEDORA">FEDORA-2010-15953</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_1623_memory_leak" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_1623_memory_leak</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apr-util">
        <vers num="0.9.1" />
        <vers num="0.9.10" />
        <vers num="0.9.11" />
        <vers num="0.9.12" />
        <vers num="0.9.13" />
        <vers num="0.9.14" />
        <vers num="0.9.15" />
        <vers num="0.9.16" />
        <vers num="0.9.17" />
        <vers num="0.9.18" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.12" />
        <vers num="1.2.13" />
        <vers num="1.2.2" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1624" published="2010-05-14" name="CVE-2010-1624" modified="2010-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=589973" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=589973</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58559" source="XF">pidgin-slp-packets-dos(58559)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2755" source="VUPEN">ADV-2010-2755</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1141" source="VUPEN" adv="1">ADV-2010-1141</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1014-1" source="UBUNTU">USN-1014-1</ref>
      <ref url="http://www.securityfocus.com/bid/40138" source="BID">40138</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0788.html" source="REDHAT">RHSA-2010:0788</ref>
      <ref url="http://www.pidgin.im/news/security/index.php?id=46" source="CONFIRM">http://www.pidgin.im/news/security/index.php?id=46</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:097" source="MANDRIVA">MDVSA-2010:097</ref>
      <ref url="http://secunia.com/advisories/41899" source="SECUNIA">41899</ref>
      <ref url="http://secunia.com/advisories/39801" source="SECUNIA" adv="1">39801</ref>
      <ref url="http://developer.pidgin.im/viewmtn/revision/info/894460d22c434e73d60b71ec031611988e687c8b" source="CONFIRM">http://developer.pidgin.im/viewmtn/revision/info/894460d22c434e73d60b71ec031611988e687c8b</ref>
      <ref url="http://developer.pidgin.im/viewmtn/revision/diff/884d44222e8c81ecec51c25e07d005e002a5479b/with/894460d22c434e73d60b71ec031611988e687c8b/libpurple/protocols/msn/slp.c" source="CONFIRM">http://developer.pidgin.im/viewmtn/revision/diff/884d44222e8c81ecec51c25e07d005e002a5479b/with/894460d22c434e73d60b71ec031611988e687c8b/libpurple/protocols/msn/slp.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":linux" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" edition="32_bit" />
        <vers num="2.4.1" edition="32_bit" />
        <vers num="2.4.2" edition="32_bit" />
        <vers num="2.4.3" edition="32_bit" />
        <vers num="2.5.0" edition="32_bit" />
        <vers num="2.5.1" />
        <vers num="2.5.2" edition="32_bit" />
        <vers num="2.5.3" edition="32_bit" />
        <vers num="2.5.4" edition="32_bit" />
        <vers num="2.5.5" edition="32_bit" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.5.9" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers prev="1" num="2.6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1625" published="2010-06-24" name="CVE-2010-1625" modified="2010-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in LXR Cross Referencer before 0.9.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the search body and the results page for a search, a different vulnerability than CVE-2009-4497 and CVE-2010-1448.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/14/3" source="MLIST">[oss-security] 20100514 Re: CVE request: lxr</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/06/2" source="MLIST">[oss-security] 20100506 Re: CVE request: lxr</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/03/7" source="MLIST">[oss-security] 20100503 Re: CVE request: lxr</ref>
      <ref url="http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.7/ChangeLog/download" source="CONFIRM">http://sourceforge.net/projects/lxr/files/stable/lxr-0.9.7/ChangeLog/download</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127316953819027&amp;w=2" source="MLIST">[oss-security] 20100506 Re: CVE request: lxr</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127289957223005&amp;w=2" source="MLIST">[oss-security] 20100503 Re: CVE request: lxr</ref>
    </refs>
    <vuln_soft>
      <prod vendor="malcom_box" name="lxr_cross_referencer">
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers prev="1" num="0.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1626" published="2010-05-21" name="CVE-2010-1626" modified="2011-01-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://bugs.mysql.com/bug.php?id=40980" source="CONFIRM" patch="1">http://bugs.mysql.com/bug.php?id=40980</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1194" source="VUPEN" adv="1">ADV-2010-1194</ref>
      <ref url="http://www.securityfocus.com/bid/40257" source="BID">40257</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0442.html" source="REDHAT">RHSA-2010:0442</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/4" source="MLIST">[oss-security] 20100518 Re: A mysql flaw.</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/10/2" source="MLIST">[oss-security] 20100510 Re: A mysql flaw.</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:101" source="MANDRIVA">MDVSA-2010:101</ref>
      <ref url="http://securitytracker.com/id?1024004" source="SECTRACK">1024004</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9490" source="OVAL">oval:org.mitre.oval:def:9490</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html" source="SUSE">SUSE-SR:2010:021</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.16a" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.20" />
        <vers num="5.0.20a" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.24a" />
        <vers num="5.0.27" />
        <vers num="5.0.33" />
        <vers num="5.0.37" />
        <vers num="5.0.41" />
        <vers num="5.0.45" />
        <vers num="5.0.45b" />
        <vers num="5.0.5.0.21" />
        <vers num="5.0.51a" />
        <vers num="5.0.51b" />
        <vers num="5.0.67" />
        <vers num="5.0.75" />
        <vers num="5.0.77" />
        <vers num="5.0.81" />
        <vers num="5.0.82" />
        <vers num="5.0.83" />
        <vers num="5.0.84" />
        <vers num="5.0.85" />
        <vers num="5.0.86" />
        <vers num="5.0.87" />
        <vers num="5.0.88" />
        <vers num="5.0.89" />
        <vers num="5.0.90" />
        <vers num="5.0.91" />
        <vers num="5.1.23" />
        <vers num="5.1.23a" />
        <vers num="5.1.30" />
        <vers num="5.1.31" />
        <vers num="5.1.32" />
        <vers num="5.1.33" />
        <vers num="5.1.34" />
        <vers num="5.1.35" />
        <vers num="5.1.36" />
        <vers num="5.1.37" />
        <vers num="5.1.38" />
        <vers num="5.1.39" />
        <vers num="5.1.40" />
        <vers num="5.1.41" />
        <vers num="5.1.42" />
        <vers num="5.1.43" />
        <vers num="5.1.44" />
        <vers prev="1" num="5.1.45" />
        <vers num="5.1.5" />
        <vers num="5.1.5a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1627" published="2010-05-19" name="CVE-2010-1627" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb.com/community/viewtopic.php?f=14&amp;t=2014195" source="CONFIRM" patch="1" adv="1">http://www.phpbb.com/community/viewtopic.php?f=14&amp;t=2014195</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/6" source="MLIST">[oss-security] 20100518 Re: CVE request: phpbb 3.0.7 and before 3.0.5</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/16/1" source="MLIST">[oss-security] 20100517 CVE request: phpbb 3.0.7 and before 3.0.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="phpbb">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1628" published="2010-05-19" name="CVE-2010-1628" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009" source="MISC">https://bugs.launchpad.net/ubuntu/+source/ghostscript/+bug/546009</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1138" source="VUPEN" adv="1">ADV-2010-1138</ref>
      <ref url="http://www.ubuntu.com/usn/USN-961-1" source="UBUNTU">USN-961-1</ref>
      <ref url="http://www.securityfocus.com/bid/40107" source="BID">40107</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511243/100/0/threaded" source="BUGTRAQ">20100512 Multiple memory corruption vulnerabilities in Ghostscript</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/7" source="MLIST">[oss-security] 20100518 Re: CVE assignment: ghostscript stack-based overflow</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/12/1" source="MLIST">[oss-security] 20100511 Re: CVE assignment: ghostscript stack-based overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:134" source="MANDRIVA">MDVSA-2010:134</ref>
      <ref url="http://secunia.com/advisories/40580" source="SECUNIA" adv="1">40580</ref>
      <ref url="http://secunia.com/advisories/39753" source="SECUNIA" adv="1">39753</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/May/134" source="FULLDISC">20100511 Multiple memory corruption vulnerabilities in Ghostscript</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://bugs.ghostscript.com/show_bug.cgi?id=691295" source="MISC">http://bugs.ghostscript.com/show_bug.cgi?id=691295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="artifex" name="gpl_ghostscript">
        <vers num="8.64" />
        <vers num="8.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1629" published="2010-05-19" name="CVE-2010-1629" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 5.2.15 allows remote attackers to inject arbitrary web script or HTML via an invalid email address.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.facebook.com/note.php?note_id=371190874581" source="CONFIRM" patch="1">http://www.facebook.com/note.php?note_id=371190874581</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/11" source="MLIST">[oss-security] 20100518 Re: CVE request: phorum &lt; 5.2.15 backend XSS</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/16/2" source="MLIST">[oss-security] 20100517 CVE request: phorum &lt; 5.2.15 backend XSS</ref>
      <ref url="http://osvdb.org/64759" source="OSVDB">64759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1_pre" />
        <vers num="3.1.1_rc2" />
        <vers num="3.1.1a" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.3a" />
        <vers num="3.2.3b" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.3.1" />
        <vers num="3.3.1a" />
        <vers num="3.3.2" />
        <vers num="3.3.2a" />
        <vers num="3.3.2b3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers num="3.4.7" />
        <vers num="3.4.8" />
        <vers num="3.4.8a" />
        <vers num="4.3.7" />
        <vers num="5.0.0_alpha" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.13a" />
        <vers num="5.0.14" />
        <vers num="5.0.14a" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1_alpha" />
        <vers num="5.0.20" />
        <vers num="5.0.2_alpha" />
        <vers num="5.0.3_beta" />
        <vers num="5.0.4_beta" />
        <vers num="5.0.4a_beta" />
        <vers num="5.0.5_beta" />
        <vers num="5.0.6_beta" />
        <vers num="5.0.7_beta" />
        <vers num="5.0.7a_beta" />
        <vers num="5.0.8_rc" />
        <vers num="5.0.9" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.17" />
        <vers num="5.1.18" />
        <vers num="5.1.20" />
        <vers num="5.1.21" />
        <vers num="5.1.25" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers num="5.2.10" edition="rc1" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.12a" />
        <vers num="5.2.13" />
        <vers prev="1" num="5.2.14" />
        <vers num="5.2.2" edition="beta" />
        <vers num="5.2.3" edition="rc1" />
        <vers num="5.2.4" edition="rc2" />
        <vers num="5.2.5" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1630" published="2010-05-19" name="CVE-2010-1630" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpbb.com/community/viewtopic.php?f=14&amp;p=9764445" source="CONFIRM" adv="1">http://www.phpbb.com/community/viewtopic.php?f=14&amp;p=9764445</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/19/5" source="MLIST">[oss-security] 20100519 Re: CVE request: phpbb 3.0.7 and before 3.0.5</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/12" source="MLIST">[oss-security] 20100518 Re: CVE request: phpbb 3.0.7 and before 3.0.5</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/16/1" source="MLIST">[oss-security] 20100517 CVE request: phpbb 3.0.7 and before 3.0.5</ref>
      <ref url="http://github.com/phpbb/phpbb3/commit/4ea3402f9363c9259881bc8ea6ce7fc6cb212657" source="MISC">http://github.com/phpbb/phpbb3/commit/4ea3402f9363c9259881bc8ea6ce7fc6cb212657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb" name="phpbb">
        <vers num="3.0.0" edition="rc1" />
        <vers num="3.0.0" edition="rc2" />
        <vers num="3.0.0" edition="rc3" />
        <vers num="3.0.0" edition="rc4" />
        <vers num="3.0.0" edition="rc5" />
        <vers num="3.0.0" edition="rc6" />
        <vers num="3.0.0" edition="rc7" />
        <vers num="3.0.0" edition="rc8" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers prev="1" num="3.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1632" published="2010-06-22" name="CVE-2010-1632" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://svn.apache.org/repos/asf/axis/axis2/java/core/security/CVE-2010-1632.pdf" source="CONFIRM">https://svn.apache.org/repos/asf/axis/axis2/java/core/security/CVE-2010-1632.pdf</ref>
      <ref url="https://issues.apache.org/jira/browse/GERONIMO-5383" source="CONFIRM">https://issues.apache.org/jira/browse/GERONIMO-5383</ref>
      <ref url="https://issues.apache.org/jira/browse/AXIS2-4450" source="CONFIRM">https://issues.apache.org/jira/browse/AXIS2-4450</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1531" source="VUPEN" adv="1">ADV-2010-1531</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1528" source="VUPEN" adv="1">ADV-2010-1528</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21433581" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21433581</ref>
      <ref url="http://secunia.com/advisories/41025" source="SECUNIA">41025</ref>
      <ref url="http://secunia.com/advisories/41016" source="SECUNIA">41016</ref>
      <ref url="http://secunia.com/advisories/40279" source="SECUNIA" adv="1">40279</ref>
      <ref url="http://secunia.com/advisories/40252" source="SECUNIA" adv="1">40252</ref>
      <ref url="http://markmail.org/message/e4yiij7lfexastvl" source="MISC">http://markmail.org/message/e4yiij7lfexastvl</ref>
      <ref url="http://geronimo.apache.org/22x-security-report.html" source="CONFIRM">http://geronimo.apache.org/22x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html" source="CONFIRM">http://geronimo.apache.org/21x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html" source="CONFIRM">http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="axis2">
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.5" />
        <vers prev="1" num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1633" published="2010-06-03" name="CVE-2010-1633" modified="2010-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1313" source="VUPEN" patch="1" adv="1">ADV-2010-1313</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=598732" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=598732</ref>
      <ref url="http://www.securityfocus.com/bid/40503" source="BID">40503</ref>
      <ref url="http://www.openssl.org/news/secadv_20100601.txt" source="CONFIRM">http://www.openssl.org/news/secadv_20100601.txt</ref>
      <ref url="http://secunia.com/advisories/40024" source="SECUNIA" adv="1">40024</ref>
      <ref url="http://cvs.openssl.org/filediff?f=openssl/crypto/rsa/rsa_pmeth.c&amp;v1=1.34&amp;v2=1.34.2.1" source="CONFIRM">http://cvs.openssl.org/filediff?f=openssl/crypto/rsa/rsa_pmeth.c&amp;v1=1.34&amp;v2=1.34.2.1</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=19693" source="CONFIRM">http://cvs.openssl.org/chngview?cn=19693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="1.0.0" edition="beta1" />
        <vers num="1.0.0" edition="beta2" />
        <vers num="1.0.0" edition="beta3" />
        <vers num="1.0.0" edition="beta4" />
        <vers num="1.0.0" edition="beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1634" published="2010-05-27" name="CVE-2010-1634" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=590690" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=590690</ref>
      <ref url="http://svn.python.org/view?rev=81079&amp;view=rev" source="CONFIRM" patch="1">http://svn.python.org/view?rev=81079&amp;view=rev</ref>
      <ref url="http://svn.python.org/view?rev=81045&amp;view=rev" source="CONFIRM" patch="1">http://svn.python.org/view?rev=81045&amp;view=rev</ref>
      <ref url="http://bugs.python.org/issue8674" source="CONFIRM" patch="1">http://bugs.python.org/issue8674</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0122" source="VUPEN">ADV-2011-0122</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1448" source="VUPEN">ADV-2010-1448</ref>
      <ref url="http://www.securityfocus.com/bid/40370" source="BID">40370</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0027.html" source="REDHAT">RHSA-2011:0027</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42888" source="SECUNIA">42888</ref>
      <ref url="http://secunia.com/advisories/40194" source="SECUNIA">40194</ref>
      <ref url="http://secunia.com/advisories/39937" source="SECUNIA" adv="1">39937</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042751.html" source="FEDORA">FEDORA-2010-9652</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python" name="python">
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1635" published="2010-06-17" name="CVE-2010-1635" modified="2010-07-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://git.samba.org/?p=samba.git;a=commit;h=25452a2268ac7013da28125f3df22085139af12d" source="CONFIRM" patch="1">http://git.samba.org/?p=samba.git;a=commit;h=25452a2268ac7013da28125f3df22085139af12d</ref>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=7229" source="CONFIRM">https://bugzilla.samba.org/show_bug.cgi?id=7229</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=594921" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=594921</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1933" source="VUPEN">ADV-2010-1933</ref>
      <ref url="http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-%28SS-2010-005%29" source="MISC">http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-(SS-2010-005)</ref>
      <ref url="http://www.securityfocus.com/bid/40097" source="BID">40097</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:141" source="MANDRIVA">MDVSA-2010:141</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1635" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1635</ref>
      <ref url="http://samba.org/samba/history/samba-3.5.2.html" source="CONFIRM">http://samba.org/samba/history/samba-3.5.2.html</ref>
      <ref url="http://samba.org/samba/history/samba-3.4.8.html" source="CONFIRM">http://samba.org/samba/history/samba-3.4.8.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14a" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
        <vers num="3.0.24" />
        <vers num="3.0.25" edition="pre1" />
        <vers num="3.0.25" edition="pre2" />
        <vers num="3.0.25" edition="rc1" />
        <vers num="3.0.25" edition="rc2" />
        <vers num="3.0.25" edition="rc3" />
        <vers num="3.0.25a" />
        <vers num="3.0.25b" />
        <vers num="3.0.25c" />
        <vers num="3.0.26" />
        <vers num="3.0.26a" />
        <vers num="3.0.27" />
        <vers num="3.0.27a" />
        <vers num="3.0.28" />
        <vers num="3.0.28a" />
        <vers num="3.0.29" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.30" />
        <vers num="3.0.31" />
        <vers num="3.0.32" />
        <vers num="3.0.33" />
        <vers num="3.0.34" />
        <vers num="3.0.35" />
        <vers num="3.0.36" />
        <vers num="3.0.37" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.10" />
        <vers num="3.2.11" />
        <vers num="3.2.12" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.2.9" />
        <vers num="3.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.10" />
        <vers num="3.3.11" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.3.9" />
        <vers num="3.4" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers prev="1" num="3.4.7" />
        <vers num="3.5" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1636" published="2010-06-07" name="CVE-2010-1636" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/linux/+bug/579585" source="MISC" patch="1">https://bugs.launchpad.net/ubuntu/+source/linux/+bug/579585</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/2" source="MLIST" patch="1">[oss-security] 20100518 kernel: btrfs: check for read permission on src file in the clone ioctl</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5dc6416414fb3ec6e2825fd4d20c8bf1d7fe0395" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=5dc6416414fb3ec6e2825fd4d20c8bf1d7fe0395</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=593226" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=593226</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/8" source="MLIST">[oss-security] 20100525 Re: kernel: btrfs: check for read permission on src file in the clone ioctl</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/18/10" source="MLIST">[oss-security] 20100518 Re: kernel: btrfs: check for read permission on src file in the clone ioctl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.30" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1637" published="2010-06-22" name="CVE-2010-1637" modified="2012-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/21/1" source="MLIST" patch="1">[oss-security] 20100621 Re: [SquirrelMail-Security] CVE Request for Horde and Squirrelmail</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/options.php?r1=13951&amp;r2=13950&amp;pathrev=13951" source="MISC" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/options.php?r1=13951&amp;r2=13950&amp;pathrev=13951</ref>
      <ref url="http://squirrelmail.org/security/issue/2010-06-21" source="CONFIRM" patch="1" adv="1">http://squirrelmail.org/security/issue/2010-06-21</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1554" source="VUPEN">ADV-2010-1554</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1536" source="VUPEN">ADV-2010-1536</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1535" source="VUPEN">ADV-2010-1535</ref>
      <ref url="http://www.securityfocus.com/bid/40307" source="BID">40307</ref>
      <ref url="http://www.securityfocus.com/bid/40291" source="BID">40291</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/9" source="MLIST">[oss-security] 20100525 Re: CVE Request for Horde and Squirrelmail</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/3" source="MLIST">[oss-security] 20100525 Re: CVE Request for Horde and Squirrelmail</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:120" source="MANDRIVA">MDVSA-2010:120</ref>
      <ref url="http://support.apple.com/kb/HT5130" source="CONFIRM">http://support.apple.com/kb/HT5130</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/functions.php?r1=13951&amp;r2=13950&amp;pathrev=13951" source="MISC">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/plugins/mail_fetch/functions.php?r1=13951&amp;r2=13950&amp;pathrev=13951</ref>
      <ref url="http://secunia.com/advisories/40307" source="SECUNIA">40307</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2012-0103.html" source="REDHAT">RHSA-2012:0103</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043261.html" source="FEDORA">FEDORA-2010-10264</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043258.html" source="FEDORA">FEDORA-2010-10259</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043239.html" source="FEDORA">FEDORA-2010-10244</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html" source="APPLE">APPLE-SA-2012-02-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3pre1" />
        <vers num="0.3pre2" />
        <vers num="0.4" />
        <vers num="0.4pre1" />
        <vers num="0.4pre2" />
        <vers num="0.5" />
        <vers num="0.5pre1" />
        <vers num="0.5pre2" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0pre1" />
        <vers num="1.0pre2" />
        <vers num="1.0pre3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.2.0" edition="rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" edition="rc1" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4.0" edition="rc1" />
        <vers num="1.4.0" edition="rc2a" />
        <vers num="1.4.0-r1" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.13" />
        <vers num="1.4.15" edition="rc1" />
        <vers num="1.4.16" />
        <vers num="1.4.17" />
        <vers num="1.4.18" />
        <vers num="1.4.19" />
        <vers num="1.4.2" />
        <vers num="1.4.2-r1" />
        <vers num="1.4.2-r2" />
        <vers num="1.4.2-r3" />
        <vers num="1.4.2-r4" />
        <vers num="1.4.2-r5" />
        <vers prev="1" num="1.4.20" />
        <vers num="1.4.3" edition="r3" />
        <vers num="1.4.3" edition="rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.3aa" />
        <vers num="1.4.4" edition="rc1" />
        <vers num="1.4.4_rc1" />
        <vers num="1.4.5" edition="rc1" />
        <vers num="1.4.6" edition="rc1" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers num="1.4.8.4fc6" />
        <vers num="1.4.9" />
        <vers num="1.4.9a" />
        <vers num="1.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1638" published="2010-06-22" name="CVE-2010-1638" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted request to an unspecified test script.  NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/2" source="MLIST">[oss-security] 20100524 Re: [core] CVE Request for Horde and Squirrelmail</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/21/2" source="MLIST">[oss-security] 20100521 Re: [core] CVE Request for Horde and Squirrelmail</ref>
    </refs>
    <vuln_soft>
      <prod vendor="horde" name="horde">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1639" published="2010-05-26" name="CVE-2010-1639" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2016" source="CONFIRM" patch="1">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2016</ref>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=commitdiff;h=f0eb394501ec21b9fe67f36cbf5db788711d4236#patch2" source="CONFIRM" patch="1">http://git.clamav.net/gitweb?p=clamav-devel.git;a=commitdiff;h=f0eb394501ec21b9fe67f36cbf5db788711d4236#patch2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58824" source="XF">clamav-clipdf-dos(58824)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1214" source="VUPEN" adv="1">ADV-2010-1214</ref>
      <ref url="http://www.securitytracker.com/id?1024017" source="SECTRACK">1024017</ref>
      <ref url="http://www.securityfocus.com/bid/40317" source="BID">40317</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:110" source="MANDRIVA">MDVSA-2010:110</ref>
      <ref url="http://secunia.com/advisories/43752" source="SECUNIA">43752</ref>
      <ref url="http://secunia.com/advisories/39895" source="SECUNIA" adv="1">39895</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055777.html" source="FEDORA">FEDORA-2011-2743</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055771.html" source="FEDORA">FEDORA-2011-2741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc" />
        <vers num="0.80" edition="rc2" />
        <vers num="0.80" edition="rc3" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" edition="rc1" />
        <vers num="0.84" edition="rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" edition="rc1" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.9" edition="rc1" />
        <vers num="0.90" edition="rc1" />
        <vers num="0.90" edition="rc1.1" />
        <vers num="0.90" edition="rc2" />
        <vers num="0.90" edition="rc3" />
        <vers num="0.90.1" />
        <vers num="0.90.2" />
        <vers num="0.91" edition="rc1" />
        <vers num="0.91" edition="rc2" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
        <vers num="0.95" edition="rc1" />
        <vers num="0.95" edition="rc2" />
        <vers num="0.95.1" />
        <vers num="0.95.2" />
        <vers num="0.95.3" />
        <vers prev="1" num="0.96" edition="rc1" />
        <vers prev="1" num="0.96" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1640" published="2010-05-26" name="CVE-2010-1640" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blobdiff;f=libclamav/pe_icons.c;h=3f1bc5be69d0f9d84e576814d1a3cc6f40c4ff2c;hp=39a714f05968f9e929576bf171dd0eb58bf06bef;hb=7f0e3bbf77382d9782e0189bf80f5f59a95779b3;hpb=f0eb394501ec21b9fe67f36cbf5db788711d4236" source="CONFIRM" patch="1">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blobdiff;f=libclamav/pe_icons.c;h=3f1bc5be69d0f9d84e576814d1a3cc6f40c4ff2c;hp=39a714f05968f9e929576bf171dd0eb58bf06bef;hb=7f0e3bbf77382d9782e0189bf80f5f59a95779b3;hpb=f0eb394501ec21b9fe67f36cbf5db788711d4236</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2031" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58825" source="XF">clamav-parseicon-dos(58825)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1214" source="VUPEN" adv="1">ADV-2010-1214</ref>
      <ref url="http://www.securityfocus.com/bid/40318" source="BID">40318</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/21/7" source="MLIST">[oss-security] 20100521 CVE Request: off by one DoS in pe_icons.c</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:110" source="MANDRIVA">MDVSA-2010:110</ref>
      <ref url="http://secunia.com/advisories/39895" source="SECUNIA" adv="1">39895</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.1" source="CONFIRM">http://git.clamav.net/gitweb?p=clamav-devel.git;a=blob_plain;f=ChangeLog;hb=clamav-0.96.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.96" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1641" published="2010-06-01" name="CVE-2010-1641" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/incr/patch-2.6.34-git9-git10.bz2" source="CONFIRM" patch="1">http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/incr/patch-2.6.34-git9-git10.bz2</ref>
      <ref url="https://www.redhat.com/archives/cluster-devel/2010-May/msg00049.html" source="MLIST">[cluster-devel] 20100525 [PATCH 3/3] GFS2: Fix permissions checking for setflags ioctl()</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=595579" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=595579</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58926" source="XF">kernel-gfs2-security-bypass(58926)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/40356" source="BID">40356</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/26/1" source="MLIST">[oss-security] 20100526 Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/12" source="MLIST">[oss-security] 20100525 Re: CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/25/1" source="MLIST">[oss-security] 20100525 CVE request - kernel: GFS2: The setflags ioctl() doesn't check file ownership</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9916" source="OVAL">oval:org.mitre.oval:def:9916</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00000.html" source="SUSE">SUSE-SA:2010:033</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7df0e0397b9a18358573274db9fdab991941062f" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7df0e0397b9a18358573274db9fdab991941062f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.2" />
        <vers num="2.6.22" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.3" />
        <vers num="2.6.32" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers prev="1" num="2.6.34" edition="git1" />
        <vers prev="1" num="2.6.34" edition="git2" />
        <vers prev="1" num="2.6.34" edition="git3" />
        <vers prev="1" num="2.6.34" edition="git4" />
        <vers prev="1" num="2.6.34" edition="git5" />
        <vers prev="1" num="2.6.34" edition="git6" />
        <vers prev="1" num="2.6.34" edition="git7" />
        <vers prev="1" num="2.6.34" edition="git8" />
        <vers prev="1" num="2.6.34" edition="git9" />
        <vers prev="1" num="2.6.34" edition="rc1" />
        <vers prev="1" num="2.6.34" edition="rc2" />
        <vers prev="1" num="2.6.34" edition="rc3" />
        <vers prev="1" num="2.6.34" edition="rc4" />
        <vers prev="1" num="2.6.34" edition="rc5" />
        <vers prev="1" num="2.6.34" edition="rc6" />
        <vers prev="1" num="2.6.34" edition="rc7" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1642" published="2010-06-17" name="CVE-2010-1642" modified="2010-07-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to trigger an out-of-bounds read, and cause a denial of service (process crash), via a \xff\xff security blob length in a Session Setup AndX request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://git.samba.org/?p=samba.git;a=commit;h=9280051bfba337458722fb157f3082f93cbd9f2b" source="CONFIRM" patch="1">http://git.samba.org/?p=samba.git;a=commit;h=9280051bfba337458722fb157f3082f93cbd9f2b</ref>
      <ref url="https://bugzilla.samba.org/show_bug.cgi?id=7254" source="CONFIRM">https://bugzilla.samba.org/show_bug.cgi?id=7254</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=594921" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=594921</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1933" source="VUPEN">ADV-2010-1933</ref>
      <ref url="http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-%28SS-2010-005%29" source="MISC">http://www.stratsec.net/Research/Advisories/Samba-Multiple-DoS-Vulnerabilities-(SS-2010-005)</ref>
      <ref url="http://www.securityfocus.com/bid/40097" source="BID">40097</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:141" source="MANDRIVA">MDVSA-2010:141</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1642" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1642</ref>
      <ref url="http://samba.org/samba/history/samba-3.5.2.html" source="CONFIRM">http://samba.org/samba/history/samba-3.5.2.html</ref>
      <ref url="http://samba.org/samba/history/samba-3.4.8.html" source="CONFIRM">http://samba.org/samba/history/samba-3.4.8.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14a" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
        <vers num="3.0.24" />
        <vers num="3.0.25" edition="pre1" />
        <vers num="3.0.25" edition="pre2" />
        <vers num="3.0.25" edition="rc1" />
        <vers num="3.0.25" edition="rc2" />
        <vers num="3.0.25" edition="rc3" />
        <vers num="3.0.25a" />
        <vers num="3.0.25b" />
        <vers num="3.0.25c" />
        <vers num="3.0.26" />
        <vers num="3.0.26a" />
        <vers num="3.0.27" />
        <vers num="3.0.27a" />
        <vers num="3.0.28" />
        <vers num="3.0.28a" />
        <vers num="3.0.29" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.30" />
        <vers num="3.0.31" />
        <vers num="3.0.32" />
        <vers num="3.0.33" />
        <vers num="3.0.34" />
        <vers num="3.0.35" />
        <vers num="3.0.36" />
        <vers num="3.0.37" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.10" />
        <vers num="3.2.11" />
        <vers num="3.2.12" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.2.9" />
        <vers num="3.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.10" />
        <vers num="3.3.11" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.3.9" />
        <vers num="3.4" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers prev="1" num="3.4.7" />
        <vers num="3.5" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1643" published="2010-06-03" name="CVE-2010-1643" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">mm/shmem.c in the Linux kernel before 2.6.28-rc3, when strict overcommit is enabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer dereference and knfsd crash) or possibly have unspecified other impact via unknown vectors.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=595970" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=595970</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58957" source="XF">linux-kernel-knfsd-dos(58957)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN" adv="1">ADV-2010-1857</ref>
      <ref url="http://www.securityfocus.com/bid/40377" source="BID">40377</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/26/6" source="MLIST">[oss-security] 20100526 Re: CVE request - kernel: nfsd: fix vm overcommit crash</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/05/26/2" source="MLIST">[oss-security] 20100526 CVE request - kernel: nfsd: fix vm overcommit crash</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:198" source="MANDRIVA">MDVSA-2010:198</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc3</ref>
      <ref url="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-knfsd-9666" source="MISC">http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-knfsd-9666</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA" adv="1">40645</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=731572d39fcd3498702eda4600db4c43d51e0b26" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=731572d39fcd3498702eda4600db4c43d51e0b26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.54" />
        <vers num="2.6.27.55" />
        <vers num="2.6.27.56" />
        <vers num="2.6.27.57" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers prev="1" num="2.6.28" edition="rc1" />
        <vers prev="1" num="2.6.28" edition="rc2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1644" published="2010-08-23" name="CVE-2010-1644" modified="2010-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1203" source="VUPEN" patch="1" adv="1">ADV-2010-1203</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0635.html" source="REDHAT">RHSA-2010:0635</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=609093" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=609093</ref>
      <ref url="http://www.securityfocus.com/bid/40332" source="BID">40332</ref>
      <ref url="http://www.securityfocus.com/archive/1/511393" source="BUGTRAQ">20100521 Cacti Multiple Parameter Cross Site Scripting Vulnerabilities</ref>
      <ref url="http://www.cacti.net/release_notes_0_8_7f.php" source="CONFIRM">http://www.cacti.net/release_notes_0_8_7f.php</ref>
      <ref url="http://svn.cacti.net/viewvc?view=rev&amp;revision=5901" source="CONFIRM">http://svn.cacti.net/viewvc?view=rev&amp;revision=5901</ref>
      <ref url="http://secunia.com/advisories/41041" source="SECUNIA" adv="1">41041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cacti" name="cacti">
        <vers num="0.5" edition="-" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6f" />
        <vers num="0.8.6g" />
        <vers num="0.8.6h" />
        <vers num="0.8.6i" />
        <vers num="0.8.6j" />
        <vers num="0.8.6k" />
        <vers num="0.8.7" />
        <vers num="0.8.7a" />
        <vers num="0.8.7b" />
        <vers num="0.8.7c" />
        <vers num="0.8.7d" />
        <vers prev="1" num="0.8.7e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1645" published="2010-08-23" name="CVE-2010-1645" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0635.html" source="REDHAT">RHSA-2010:0635</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=609115" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=609115</ref>
      <ref url="http://www.cacti.net/release_notes_0_8_7f.php" source="CONFIRM">http://www.cacti.net/release_notes_0_8_7f.php</ref>
      <ref url="http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php" source="MISC">http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php</ref>
      <ref url="http://svn.cacti.net/viewvc?view=rev&amp;revision=5784" source="CONFIRM">http://svn.cacti.net/viewvc?view=rev&amp;revision=5784</ref>
      <ref url="http://svn.cacti.net/viewvc?view=rev&amp;revision=5782" source="CONFIRM">http://svn.cacti.net/viewvc?view=rev&amp;revision=5782</ref>
      <ref url="http://svn.cacti.net/viewvc?view=rev&amp;revision=5778" source="CONFIRM">http://svn.cacti.net/viewvc?view=rev&amp;revision=5778</ref>
      <ref url="http://secunia.com/advisories/41041" source="SECUNIA" adv="1">41041</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cacti" name="cacti">
        <vers num="0.5" edition="-" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6f" />
        <vers num="0.8.6g" />
        <vers num="0.8.6h" />
        <vers num="0.8.6i" />
        <vers num="0.8.6j" />
        <vers num="0.8.6k" />
        <vers num="0.8.7" />
        <vers num="0.8.7a" />
        <vers num="0.8.7b" />
        <vers num="0.8.7c" />
        <vers num="0.8.7d" />
        <vers prev="1" num="0.8.7e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1646" published="2010-06-07" name="CVE-2010-1646" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.sudo.ws/repos/sudo/rev/a09c6812eaec" source="CONFIRM" patch="1">http://www.sudo.ws/repos/sudo/rev/a09c6812eaec</ref>
      <ref url="http://www.sudo.ws/repos/sudo/rev/3057fde43cf0" source="CONFIRM" patch="1">http://www.sudo.ws/repos/sudo/rev/3057fde43cf0</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=598154" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=598154</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1519" source="VUPEN">ADV-2010-1519</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1518" source="VUPEN">ADV-2010-1518</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1478" source="VUPEN">ADV-2010-1478</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1452" source="VUPEN">ADV-2010-1452</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/secure_path.html" source="CONFIRM" adv="1">http://www.sudo.ws/sudo/alerts/secure_path.html</ref>
      <ref url="http://www.securitytracker.com/id?1024101" source="SECTRACK">1024101</ref>
      <ref url="http://www.securityfocus.com/bid/40538" source="BID">40538</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514489/100/0/threaded" source="BUGTRAQ">20101027 rPSA-2010-0075-1 sudo</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0475.html" source="REDHAT">RHSA-2010:0475</ref>
      <ref url="http://www.osvdb.org/65083" source="OSVDB">65083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:118" source="MANDRIVA">MDVSA-2010:118</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2062" source="DEBIAN">DSA-2062</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2010-0075" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2010-0075</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201009-03.xml" source="GENTOO">GLSA-201009-03</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40508" source="SECUNIA">40508</ref>
      <ref url="http://secunia.com/advisories/40215" source="SECUNIA">40215</ref>
      <ref url="http://secunia.com/advisories/40188" source="SECUNIA">40188</ref>
      <ref url="http://secunia.com/advisories/40002" source="SECUNIA" adv="1">40002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7338" source="OVAL">oval:org.mitre.oval:def:7338</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10580" source="OVAL">oval:org.mitre.oval:def:10580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043026.html" source="FEDORA">FEDORA-2010-9415</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043012.html" source="FEDORA">FEDORA-2010-9417</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042838.html" source="FEDORA">FEDORA-2010-9402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.3.1" />
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.2p1" />
        <vers num="1.6.2p2" />
        <vers num="1.6.2p3" />
        <vers num="1.6.3" />
        <vers num="1.6.3p1" />
        <vers num="1.6.3p2" />
        <vers num="1.6.3p3" />
        <vers num="1.6.3p4" />
        <vers num="1.6.3p5" />
        <vers num="1.6.3p6" />
        <vers num="1.6.3p7" />
        <vers num="1.6.4" />
        <vers num="1.6.4p1" />
        <vers num="1.6.4p2" />
        <vers num="1.6.5" />
        <vers num="1.6.5p1" />
        <vers num="1.6.5p2" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.7p1" />
        <vers num="1.6.7p2" />
        <vers num="1.6.7p3" />
        <vers num="1.6.7p4" />
        <vers num="1.6.7p5" />
        <vers num="1.6.8" />
        <vers num="1.6.8p1" />
        <vers num="1.6.8p10" />
        <vers num="1.6.8p11" />
        <vers num="1.6.8p12" />
        <vers num="1.6.8p2" />
        <vers num="1.6.8p3" />
        <vers num="1.6.8p4" />
        <vers num="1.6.8p5" />
        <vers num="1.6.8p6" />
        <vers num="1.6.8p7" />
        <vers num="1.6.8p8" />
        <vers num="1.6.8p9" />
        <vers num="1.6.9" />
        <vers num="1.6.9p1" />
        <vers num="1.6.9p10" />
        <vers num="1.6.9p11" />
        <vers num="1.6.9p12" />
        <vers num="1.6.9p13" />
        <vers num="1.6.9p14" />
        <vers num="1.6.9p15" />
        <vers num="1.6.9p16" />
        <vers num="1.6.9p17" />
        <vers num="1.6.9p18" />
        <vers num="1.6.9p19" />
        <vers num="1.6.9p2" />
        <vers num="1.6.9p20" />
        <vers num="1.6.9p21" />
        <vers num="1.6.9p22" />
        <vers num="1.6.9p3" />
        <vers num="1.6.9p4" />
        <vers num="1.6.9p5" />
        <vers num="1.6.9p6" />
        <vers num="1.6.9p7" />
        <vers num="1.6.9p8" />
        <vers num="1.6.9p9" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.2p1" />
        <vers num="1.7.2p2" />
        <vers num="1.7.2p3" />
        <vers num="1.7.2p4" />
        <vers num="1.7.2p5" />
        <vers num="1.7.2p6" />
        <vers num="1.7.2p7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1647" published="2010-06-07" name="CVE-2010-1647" modified="2010-07-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) strings that are processed as script by Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.wikimedia.org/show_bug.cgi?id=23687" source="CONFIRM">https://bugzilla.wikimedia.org/show_bug.cgi?id=23687</ref>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html" source="MLIST">[MediaWiki-announce] 20100528 MediaWiki security update: 1.15.4 and 1.16.0beta3</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html" source="FEDORA">FEDORA-2010-10848</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html" source="FEDORA">FEDORA-2010-10779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.15.0" edition="rc1" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.3" />
        <vers num="1.16.0" edition="beta1" />
        <vers num="1.16.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1648" published="2010-06-07" name="CVE-2010-1648" modified="2010-07-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the login interface in MediaWiki 1.15 before 1.15.4 and 1.16 before 1.16 beta 3 allows remote attackers to hijack the authentication of users for requests that (1) create accounts or (2) reset passwords, related to the Special:Userlogin form.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2010-May/000091.html" source="MLIST" patch="1" adv="1">[MediaWiki-announce] 20100528 MediaWiki security update: 1.15.4 and 1.16.0beta3</ref>
      <ref url="https://bugzilla.wikimedia.org/show_bug.cgi?id=23371" source="CONFIRM">https://bugzilla.wikimedia.org/show_bug.cgi?id=23371</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043856.html" source="FEDORA">FEDORA-2010-10848</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043803.html" source="FEDORA">FEDORA-2010-10779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.15.0" edition="rc1" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.3" />
        <vers num="1.16.0" edition="beta1" />
        <vers num="1.16.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1649" published="2010-06-07" name="CVE-2010-1649" modified="2010-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the back end in Joomla! 1.5 through 1.5.17 allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "various administrator screens," possibly the search parameter in administrator/index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40444" source="BID">40444</ref>
      <ref url="http://www.osvdb.org/65011" source="OSVDB">65011</ref>
      <ref url="http://secunia.com/advisories/39964" source="SECUNIA" adv="1">39964</ref>
      <ref url="http://developer.joomla.org/security/news/314-20100501-core-xss-vulnerabilities-in-back-end.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+JoomlaSecurityNews+%28Joomla%21+Security+News%29" source="CONFIRM">http://developer.joomla.org/security/news/314-20100501-core-xss-vulnerabilities-in-back-end.html?utm_source=feedburner&amp;utm_medium=email&amp;utm_campaign=Feed%3A+JoomlaSecurityNews+%28Joomla!+Security+News%29</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla!">
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.10" />
        <vers num="1.5.11" />
        <vers num="1.5.12" />
        <vers num="1.5.13" />
        <vers num="1.5.14" />
        <vers num="1.5.15" />
        <vers num="1.5.16" />
        <vers num="1.5.17" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1650" published="2010-05-03" name="CVE-2010-1650" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" source="AIXAPAR" patch="1">PM12247</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58323" source="XF">ibm-was-debugging-information-disclosure(58323)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0994" source="VUPEN">ADV-2010-0994</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM06839" source="AIXAPAR">PM06839</ref>
      <ref url="http://secunia.com/advisories/39628" source="SECUNIA" adv="1">39628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.35" />
        <vers num="6.0.2.37" />
        <vers num="6.0.2.39" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.24" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.26" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="6.1.1" />
        <vers num="6.1.13" />
        <vers num="6.1.14" />
        <vers num="6.1.3" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1651" published="2010-05-03" name="CVE-2010-1651" modified="2010-06-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247" source="AIXAPAR" patch="1">PM12247</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58324" source="XF">ibm-was-trace-information-disclosure(58324)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1411" source="VUPEN">ADV-2010-1411</ref>
      <ref url="http://www.osvdb.org/65437" source="OSVDB">65437</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829" source="AIXAPAR">PM15829</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM08892" source="AIXAPAR">PM08892</ref>
      <ref url="http://secunia.com/advisories/40096" source="SECUNIA">40096</ref>
      <ref url="http://secunia.com/advisories/39628" source="SECUNIA" adv="1">39628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.24" />
        <vers num="6.1.0.25" />
        <vers num="6.1.0.26" />
        <vers num="6.1.0.27" />
        <vers num="6.1.0.29" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="6.1.1" />
        <vers num="6.1.13" />
        <vers num="6.1.14" />
        <vers num="6.1.3" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.5" />
        <vers num="7.0.0.7" />
        <vers num="7.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1652" published="2010-05-03" name="CVE-2010-1652" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1009" source="VUPEN" adv="1">ADV-2010-1009</ref>
      <ref url="http://www.securityfocus.com/bid/39732" source="BID">39732</ref>
      <ref url="http://www.exploit-db.com/exploits/12421" source="EXPLOIT-DB">12421</ref>
      <ref url="http://secunia.com/advisories/39615" source="SECUNIA" adv="1">39615</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/helpcenterlive-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/helpcenterlive-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helpcenterlive" name="hcl">
        <vers num="2.0.6" />
        <vers num="2.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1653" published="2010-05-03" name="CVE-2010-1653" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1004" source="VUPEN" adv="1">ADV-2010-1004</ref>
      <ref url="http://www.securityfocus.com/bid/39743" source="BID">39743</ref>
      <ref url="http://www.exploit-db.com/exploits/12430" source="EXPLOIT-DB">12430</ref>
      <ref url="http://secunia.com/advisories/39585" source="SECUNIA" adv="1">39585</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlagraphics-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlagraphics-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htmlcoderhelper" name="com_graphics">
        <vers num="1.0.6" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1654" published="2010-05-03" name="CVE-2010-1654" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1014" source="VUPEN" adv="1">ADV-2010-1014</ref>
      <ref url="http://www.securityfocus.com/bid/39731" source="BID">39731</ref>
      <ref url="http://www.exploit-db.com/exploits/12415" source="EXPLOIT-DB">12415</ref>
      <ref url="http://secunia.com/advisories/39625" source="SECUNIA" adv="1">39625</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/ireee-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/ireee-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="instantrankingseo" name="infocus_real_estate">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1655" published="2010-05-03" name="CVE-2010-1655" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in User/User_ChkLogin.asp in PowerEasy 2006 and PowerEasy SiteWeaver 6.8 allows remote attackers to inject arbitrary web script or HTML via the ComeUrl parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39696" source="BID">39696</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510927/100/0/threaded" source="BUGTRAQ">20100424 A XSS in User_ChkLogin.asp of PowerEasy 2006</ref>
      <ref url="http://secunia.com/advisories/39627" source="SECUNIA" adv="1">39627</ref>
      <ref url="http://osvdb.org/64094" source="OSVDB">64094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powereasy" name="siteweaver">
        <vers num="2006" />
        <vers num="6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1656" published="2010-05-03" name="CVE-2010-1656" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58178" source="XF">abc-index-sql-injection(58178)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1005" source="VUPEN" adv="1">ADV-2010-1005</ref>
      <ref url="http://www.securityfocus.com/bid/39741" source="BID">39741</ref>
      <ref url="http://www.exploit-db.com/exploits/12429" source="EXPLOIT-DB">12429</ref>
      <ref url="http://secunia.com/advisories/39588" source="SECUNIA" adv="1">39588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="airiny" name="com_abc">
        <vers num="1.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1657" published="2010-05-03" name="CVE-2010-1657" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58175" source="XF">comsmartsite-controller-file-include(58175)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1006" source="VUPEN" adv="1">ADV-2010-1006</ref>
      <ref url="http://www.securityfocus.com/bid/39740" source="BID">39740</ref>
      <ref url="http://www.exploit-db.com/exploits/12428" source="EXPLOIT-DB">12428</ref>
      <ref url="http://secunia.com/advisories/39592" source="SECUNIA" adv="1">39592</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlasmartsite-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlasmartsite-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recly" name="com_smartsite">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1658" published="2010-05-03" name="CVE-2010-1658" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58176" source="XF">comnoticeboard-controller-file-include(58176)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1007" source="VUPEN" adv="1">ADV-2010-1007</ref>
      <ref url="http://www.securityfocus.com/bid/39742" source="BID">39742</ref>
      <ref url="http://www.exploit-db.com/exploits/12427" source="EXPLOIT-DB">12427</ref>
      <ref url="http://secunia.com/advisories/39600" source="SECUNIA" adv="1">39600</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlnoticeboard-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlnoticeboard-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="code-garage" name="com_noticeboard">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1659" published="2010-05-03" name="CVE-2010-1659" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58177" source="XF">ultimateportfolio-controller-file-include(58177)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1008" source="VUPEN" adv="1">ADV-2010-1008</ref>
      <ref url="http://www.securityfocus.com/bid/39739" source="BID">39739</ref>
      <ref url="http://www.exploit-db.com/exploits/12426" source="EXPLOIT-DB">12426</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaultimateportfolio-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaultimateportfolio-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webkul" name="com_ultimateportfolio">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1660" published="2010-05-03" name="CVE-2010-1660" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58181" source="XF">classifiedsscript-helpdetails-sql-injection(58181)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1010" source="VUPEN" adv="1">ADV-2010-1010</ref>
      <ref url="http://www.securityfocus.com/bid/39737" source="BID">39737</ref>
      <ref url="http://www.exploit-db.com/exploits/12423" source="EXPLOIT-DB">12423</ref>
      <ref url="http://secunia.com/advisories/39612" source="SECUNIA" adv="1">39612</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/clscriptclassfieds-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/clscriptclassfieds-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clscript" name="clscript_classifieds_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1661" published="2010-05-03" name="CVE-2010-1661" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58184" source="XF">phpquickarcade-arcade-sql-injection(58184)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1013" source="VUPEN" adv="1">ADV-2010-1013</ref>
      <ref url="http://www.securityfocus.com/bid/39733" source="BID">39733</ref>
      <ref url="http://www.exploit-db.com/exploits/12416" source="EXPLOIT-DB">12416</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/phpquickarcade-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/phpquickarcade-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jcink" name="php-quick-arcade">
        <vers num="3.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1662" published="2010-05-03" name="CVE-2010-1662" modified="2010-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58185" source="XF">phpquickarcade-acpmoderate-xss(58185)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1013" source="VUPEN" adv="1">ADV-2010-1013</ref>
      <ref url="http://www.securityfocus.com/bid/39733" source="BID">39733</ref>
      <ref url="http://www.exploit-db.com/exploits/12416" source="EXPLOIT-DB">12416</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/phpquickarcade-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/phpquickarcade-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jcink" name="php-quick-arcade">
        <vers num="3.0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1663" published="2010-05-03" name="CVE-2010-1663" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1016" source="VUPEN" adv="1">ADV-2010-1016</ref>
      <ref url="http://secunia.com/advisories/39651" source="SECUNIA" adv="1">39651</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6813" source="OVAL">oval:org.mitre.oval:def:6813</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40445" source="CONFIRM">http://bugs.chromium.org/40445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers prev="1" num="4.1.249.1063" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1664" published="2010-05-03" name="CVE-2010-1664" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1016" source="VUPEN" patch="1" adv="1">ADV-2010-1016</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/39651" source="SECUNIA" adv="1">39651</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6878" source="OVAL">oval:org.mitre.oval:def:6878</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html</ref>
      <ref url="http://bugs.chromium.org/40487" source="CONFIRM">http://bugs.chromium.org/40487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers prev="1" num="4.1.249.1063" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1665" published="2010-05-03" name="CVE-2010-1665" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1016" source="VUPEN" adv="1">ADV-2010-1016</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/39651" source="SECUNIA" adv="1">39651</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7034" source="OVAL">oval:org.mitre.oval:def:7034</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/04/stable-update-bug-and-security-fixes.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=42294" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=42294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers prev="1" num="4.1.249.1063" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1666" published="2010-07-02" name="CVE-2010-1666" modified="2010-07-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Dan Pascu python-cjson 1.0.5, when UCS-4 encoding is enabled, allows context-dependent attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors involving crafted Unicode input to the cjson.encode function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/python-cjson/+bug/585274" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/python-cjson/+bug/585274</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1774" source="VUPEN">ADV-2010-1774</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2068" source="DEBIAN">DSA-2068</ref>
      <ref url="http://secunia.com/advisories/40500" source="SECUNIA">40500</ref>
      <ref url="http://secunia.com/advisories/40335" source="SECUNIA" adv="1">40335</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dan_pascu" name="python-cjson">
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1667" published="2010-07-06" name="CVE-2010-1667" modified="2010-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41319" source="BID" patch="1">41319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59993" source="XF">mahara-multiple-unspecified-xss(59993)</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.2.5" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.2.5</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.1.9" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.1.9</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.0.15" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.0.15</ref>
      <ref url="http://secunia.com/advisories/40431" source="SECUNIA" adv="1">40431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers prev="1" num="1.0.14" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" edition="alpha1" />
        <vers num="1.2.0" edition="alpha2" />
        <vers num="1.2.0" edition="alpha3" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1668" published="2010-07-06" name="CVE-2010-1668" modified="2010-10-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59994" source="XF">mahara-multiple-unspecified-csrf(59994)</ref>
      <ref url="http://www.securityfocus.com/bid/41319" source="BID">41319</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.2.5" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.2.5</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.1.9" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.1.9</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.0.15" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.0.15</ref>
      <ref url="http://secunia.com/advisories/40431" source="SECUNIA" adv="1">40431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers prev="1" num="1.0.14" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" edition="alpha1" />
        <vers num="1.2.0" edition="alpha2" />
        <vers num="1.2.0" edition="alpha3" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1669" published="2010-07-06" name="CVE-2010-1669" modified="2010-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41319" source="BID" patch="1">41319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59995" source="XF">mahara-unspecified-sql-injection(59995)</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.2.5" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.2.5</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.1.9" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.1.9</ref>
      <ref url="http://secunia.com/advisories/40431" source="SECUNIA" adv="1">40431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" edition="alpha1" />
        <vers num="1.2.0" edition="alpha2" />
        <vers num="1.2.0" edition="alpha3" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1670" published="2010-07-06" name="CVE-2010-1670" modified="2010-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass authentication via an empty password.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41319" source="BID">41319</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.2.5" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.2.5</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.1.9" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.1.9</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.0.15" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.0.15</ref>
      <ref url="http://secunia.com/advisories/40431" source="SECUNIA" adv="1">40431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers prev="1" num="1.0.14" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.2.0" edition="alpha1" />
        <vers num="1.2.0" edition="alpha2" />
        <vers num="1.2.0" edition="alpha3" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1671" published="2010-08-02" name="CVE-2010-1671" modified="2010-08-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via shell metacharacters in command-line arguments, as demonstrated by the second argument in a down action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/66649" source="OSVDB">66649</ref>
      <ref url="http://secunia.com/advisories/40713" source="SECUNIA" adv="1">40713</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590670" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pharscape" name="hsolink">
        <vers num="1.0.118" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1674" published="2011-03-29" name="CVE-2010-1674" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html 
'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=654603" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=654603</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66211" source="XF">quagga-community-dos(66211)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0711" source="VUPEN" adv="1">ADV-2011-0711</ref>
      <ref url="http://www.securityfocus.com/bid/46942" source="BID">46942</ref>
      <ref url="http://www.quagga.net/news2.php?y=2011&amp;m=3&amp;d=21#id1300723200" source="CONFIRM">http://www.quagga.net/news2.php?y=2011&amp;m=3&amp;d=21#id1300723200</ref>
      <ref url="http://www.osvdb.org/71259" source="OSVDB">71259</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:058" source="MANDRIVA">MDVSA-2011:058</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2197" source="DEBIAN">DSA-2197</ref>
      <ref url="http://secunia.com/advisories/43770" source="SECUNIA" adv="1">43770</ref>
      <ref url="http://secunia.com/advisories/43499" source="SECUNIA" adv="1">43499</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00009.html" source="SUSE">SUSE-SU-2011:1316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.1" />
        <vers num="0.96.2" />
        <vers num="0.96.3" />
        <vers num="0.96.4" />
        <vers num="0.96.5" />
        <vers num="0.97.0" />
        <vers num="0.97.1" />
        <vers num="0.97.2" />
        <vers num="0.97.3" />
        <vers num="0.97.4" />
        <vers num="0.97.5" />
        <vers num="0.98.0" />
        <vers num="0.98.1" />
        <vers num="0.98.2" />
        <vers num="0.98.3" />
        <vers num="0.98.4" />
        <vers num="0.98.5" />
        <vers num="0.98.6" />
        <vers num="0.99.1" />
        <vers num="0.99.10" />
        <vers num="0.99.11" />
        <vers num="0.99.12" />
        <vers num="0.99.13" />
        <vers num="0.99.14" />
        <vers num="0.99.15" />
        <vers num="0.99.16" />
        <vers prev="1" num="0.99.17" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="0.99.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1675" published="2011-03-29" name="CVE-2010-1675" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=654614" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=654614</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66212" source="XF">quagga-aspath-dos(66212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0711" source="VUPEN" adv="1">ADV-2011-0711</ref>
      <ref url="http://www.securityfocus.com/bid/46943" source="BID">46943</ref>
      <ref url="http://www.quagga.net/news2.php?y=2011&amp;m=3&amp;d=21#id1300723200" source="CONFIRM">http://www.quagga.net/news2.php?y=2011&amp;m=3&amp;d=21#id1300723200</ref>
      <ref url="http://www.osvdb.org/71258" source="OSVDB">71258</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:058" source="MANDRIVA">MDVSA-2011:058</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2197" source="DEBIAN">DSA-2197</ref>
      <ref url="http://secunia.com/advisories/43770" source="SECUNIA" adv="1">43770</ref>
      <ref url="http://secunia.com/advisories/43499" source="SECUNIA" adv="1">43499</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00009.html" source="SUSE">SUSE-SU-2011:1316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.1" />
        <vers num="0.96.2" />
        <vers num="0.96.3" />
        <vers num="0.96.4" />
        <vers num="0.96.5" />
        <vers num="0.97.0" />
        <vers num="0.97.1" />
        <vers num="0.97.2" />
        <vers num="0.97.3" />
        <vers num="0.97.4" />
        <vers num="0.97.5" />
        <vers num="0.98.0" />
        <vers num="0.98.1" />
        <vers num="0.98.2" />
        <vers num="0.98.3" />
        <vers num="0.98.4" />
        <vers num="0.98.5" />
        <vers num="0.98.6" />
        <vers num="0.99.1" />
        <vers num="0.99.10" />
        <vers num="0.99.11" />
        <vers num="0.99.12" />
        <vers num="0.99.13" />
        <vers num="0.99.14" />
        <vers num="0.99.15" />
        <vers num="0.99.16" />
        <vers prev="1" num="0.99.17" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="0.99.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1676" published="2010-12-21" name="CVE-2010-1676" modified="2011-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://blog.torproject.org/blog/tor-02220-alpha-out-security-patches" source="CONFIRM" patch="1">http://blog.torproject.org/blog/tor-02220-alpha-out-security-patches</ref>
      <ref url="http://blog.torproject.org/blog/tor-02128-released-security-patches" source="CONFIRM" patch="1">http://blog.torproject.org/blog/tor-02128-released-security-patches</ref>
      <ref url="http://archives.seul.org/or/announce/Dec-2010/msg00000.html" source="MLIST" patch="1">[or-announce] 20101220 Tor 0.2.1.28 is released (security patches)</ref>
      <ref url="https://gitweb.torproject.org/tor.git/blob/release-0.2.1:/ChangeLog" source="CONFIRM">https://gitweb.torproject.org/tor.git/blob/release-0.2.1:/ChangeLog</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0114" source="VUPEN">ADV-2011-0114</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3290" source="VUPEN" adv="1">ADV-2010-3290</ref>
      <ref url="http://www.securityfocus.com/bid/45500" source="BID">45500</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2136" source="DEBIAN">DSA-2136</ref>
      <ref url="http://securitytracker.com/id?1024910" source="SECTRACK">1024910</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-02.xml" source="GENTOO">GLSA-201101-02</ref>
      <ref url="http://secunia.com/advisories/42916" source="SECUNIA">42916</ref>
      <ref url="http://secunia.com/advisories/42783" source="SECUNIA">42783</ref>
      <ref url="http://secunia.com/advisories/42667" source="SECUNIA">42667</ref>
      <ref url="http://secunia.com/advisories/42536" source="SECUNIA" adv="1">42536</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052690.html" source="FEDORA">FEDORA-2010-19147</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052657.html" source="FEDORA">FEDORA-2010-19159</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2" />
        <vers num="0.0.2_pre13" />
        <vers num="0.0.2_pre14" />
        <vers num="0.0.2_pre15" />
        <vers num="0.0.2_pre16" />
        <vers num="0.0.2_pre17" />
        <vers num="0.0.2_pre18" />
        <vers num="0.0.2_pre19" />
        <vers num="0.0.2_pre20" />
        <vers num="0.0.2_pre21" />
        <vers num="0.0.2_pre22" />
        <vers num="0.0.2_pre23" />
        <vers num="0.0.2_pre24" />
        <vers num="0.0.2_pre25" />
        <vers num="0.0.2_pre26" />
        <vers num="0.0.2_pre27" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.6.1" />
        <vers num="0.0.6.2" />
        <vers num="0.0.7" />
        <vers num="0.0.7.1" />
        <vers num="0.0.7.2" />
        <vers num="0.0.7.3" />
        <vers num="0.0.8" />
        <vers num="0.0.8.1" />
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.10" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
        <vers num="0.1.0.1" />
        <vers num="0.1.0.10" />
        <vers num="0.1.0.11" />
        <vers num="0.1.0.12" />
        <vers num="0.1.0.13" />
        <vers num="0.1.0.14" />
        <vers num="0.1.0.15" />
        <vers num="0.1.0.16" />
        <vers num="0.1.0.17" />
        <vers num="0.1.0.18" />
        <vers num="0.1.0.19" />
        <vers num="0.1.0.2" />
        <vers num="0.1.0.3" />
        <vers num="0.1.0.4" />
        <vers num="0.1.0.5" />
        <vers num="0.1.0.6" />
        <vers num="0.1.0.7" />
        <vers num="0.1.0.8" />
        <vers num="0.1.0.9" />
        <vers num="0.1.1" />
        <vers num="0.1.1.1" />
        <vers num="0.1.1.10" />
        <vers num="0.1.1.10_alpha" />
        <vers num="0.1.1.11" />
        <vers num="0.1.1.12" />
        <vers num="0.1.1.13" />
        <vers num="0.1.1.14" />
        <vers num="0.1.1.15" />
        <vers num="0.1.1.16" />
        <vers num="0.1.1.17" />
        <vers num="0.1.1.18" />
        <vers num="0.1.1.19" />
        <vers num="0.1.1.1_alpha" />
        <vers num="0.1.1.2" />
        <vers num="0.1.1.20" />
        <vers num="0.1.1.21" />
        <vers num="0.1.1.22" />
        <vers num="0.1.1.23" />
        <vers num="0.1.1.25" />
        <vers num="0.1.1.26" />
        <vers num="0.1.1.2_alpha" />
        <vers num="0.1.1.3" />
        <vers num="0.1.1.3_alpha" />
        <vers num="0.1.1.4" />
        <vers num="0.1.1.4_alpha" />
        <vers num="0.1.1.5" />
        <vers num="0.1.1.5_alpha" />
        <vers num="0.1.1.6" />
        <vers num="0.1.1.6_alpha" />
        <vers num="0.1.1.7" />
        <vers num="0.1.1.7_alpha" />
        <vers num="0.1.1.8" />
        <vers num="0.1.1.8_alpha" />
        <vers num="0.1.1.9" />
        <vers num="0.1.1.9_alpha" />
        <vers num="0.1.2.10" />
        <vers num="0.1.2.11" />
        <vers num="0.1.2.12" />
        <vers num="0.1.2.13" />
        <vers num="0.1.2.14" />
        <vers num="0.1.2.16" />
        <vers num="0.1.2.18" />
        <vers num="0.1.2.19" />
        <vers num="0.1.2.1_alpha-cvs" />
        <vers num="0.1.2.2" />
        <vers num="0.1.2.30" />
        <vers num="0.1.2.4" />
        <vers num="0.1.2.5" edition="alpha" />
        <vers num="0.1.2.7" edition="alpha" />
        <vers num="0.1.2.9" />
        <vers num="0.2.1.1.12" />
        <vers num="0.2.1.1.13" />
        <vers num="0.2.1.1.14" />
        <vers num="0.2.1.1.15" />
        <vers num="0.2.1.1.16" />
        <vers num="0.2.1.1.17" />
        <vers num="0.2.1.1.18" />
        <vers num="0.2.1.1.19" />
        <vers num="0.2.1.1.20" />
        <vers num="0.2.1.1.21" />
        <vers num="0.2.1.1.22" />
        <vers num="0.2.1.1.23" />
        <vers num="0.2.1.1.24" />
        <vers num="0.2.1.1.25" />
        <vers num="0.2.1.1.26" />
        <vers prev="1" num="0.2.1.1.27" />
        <vers num="0.2.2.1" edition="alpha" />
        <vers num="0.2.2.10" edition="alpha" />
        <vers num="0.2.2.11" edition="alpha" />
        <vers num="0.2.2.12" edition="alpha" />
        <vers num="0.2.2.13" edition="alpha" />
        <vers num="0.2.2.14" edition="alpha" />
        <vers num="0.2.2.15" edition="alpha" />
        <vers num="0.2.2.16" edition="alpha" />
        <vers num="0.2.2.17" edition="alpha" />
        <vers num="0.2.2.18" edition="alpha" />
        <vers num="0.2.2.19" edition="alpha" />
        <vers num="0.2.2.2" edition="alpha" />
        <vers num="0.2.2.3" edition="alpha" />
        <vers num="0.2.2.4" edition="alpha" />
        <vers num="0.2.2.5" edition="alpha" />
        <vers num="0.2.2.6" edition="alpha" />
        <vers num="0.2.2.7" edition="alpha" />
        <vers num="0.2.2.8" edition="alpha" />
        <vers num="0.2.2.9" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1677" published="2011-01-03" name="CVE-2010-1677" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demonstrated by a &lt;bo&lt;bo&lt;bo&lt;bo&lt;body>dy>dy>dy>dy> sequence, a different vulnerability than CVE-2010-4524.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64656" source="XF">mhonarc-start-tags-dos(64656)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0067" source="VUPEN">ADV-2011-0067</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3344" source="VUPEN" adv="1">ADV-2010-3344</ref>
      <ref url="http://www.mail-archive.com/mhonarc-dev@mhonarc.org/msg01297.html" source="MLIST">[mhonarc-dev] 20101230 [bug #32014] CVE-2010-1677: DoS when processing html messages with deep tag nesting</ref>
      <ref url="http://secunia.com/advisories/42694" source="SECUNIA">42694</ref>
      <ref url="http://savannah.nongnu.org/bugs/?32014" source="CONFIRM">http://savannah.nongnu.org/bugs/?32014</ref>
      <ref url="http://lists.mandriva.com/security-announce/2011-01/msg00004.php" source="MANDRIVA">MDVSA-2011:003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mhonarc" name="mhonarc">
        <vers num="2.6.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1679" published="2011-01-10" name="CVE-2010-1679" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0 package.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64615" source="XF">dpkg-dpkgsource-directory-traversal(64615)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0196" source="VUPEN">ADV-2011-0196</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0044" source="VUPEN" adv="1">ADV-2011-0044</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0040" source="VUPEN" adv="1">ADV-2011-0040</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1038-1" source="UBUNTU">USN-1038-1</ref>
      <ref url="http://www.securityfocus.com/bid/45703" source="BID">45703</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2142" source="DEBIAN" adv="1">DSA-2142</ref>
      <ref url="http://secunia.com/advisories/43054" source="SECUNIA">43054</ref>
      <ref url="http://secunia.com/advisories/42831" source="SECUNIA" adv="1">42831</ref>
      <ref url="http://secunia.com/advisories/42826" source="SECUNIA" adv="1">42826</ref>
      <ref url="http://osvdb.org/70368" source="OSVDB">70368</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053311.html" source="FEDORA">FEDORA-2011-0345</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053306.html" source="FEDORA">FEDORA-2011-0362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="dpkg">
        <vers num="1.10" />
        <vers num="1.10.1" />
        <vers num="1.10.10" />
        <vers num="1.10.11" />
        <vers num="1.10.12" />
        <vers num="1.10.13" />
        <vers num="1.10.14" />
        <vers num="1.10.15" />
        <vers num="1.10.16" />
        <vers num="1.10.17" />
        <vers num="1.10.18" />
        <vers num="1.10.18.1" />
        <vers num="1.10.19" />
        <vers num="1.10.2" />
        <vers num="1.10.20" />
        <vers num="1.10.21" />
        <vers num="1.10.22" />
        <vers num="1.10.23" />
        <vers num="1.10.24" />
        <vers num="1.10.25" />
        <vers num="1.10.26" />
        <vers num="1.10.27" />
        <vers num="1.10.28" />
        <vers num="1.10.3" />
        <vers num="1.10.4" />
        <vers num="1.10.5" />
        <vers num="1.10.6" />
        <vers num="1.10.7" />
        <vers num="1.10.8" />
        <vers num="1.10.9" />
        <vers num="1.13.0" />
        <vers num="1.13.1" />
        <vers num="1.13.10" />
        <vers num="1.13.11" />
        <vers num="1.13.11.1" />
        <vers num="1.13.12" />
        <vers num="1.13.13" />
        <vers num="1.13.14" />
        <vers num="1.13.15" />
        <vers num="1.13.16" />
        <vers num="1.13.17" />
        <vers num="1.13.18" />
        <vers num="1.13.19" />
        <vers num="1.13.2" />
        <vers num="1.13.20" />
        <vers num="1.13.21" />
        <vers num="1.13.22" />
        <vers num="1.13.23" />
        <vers num="1.13.24" />
        <vers num="1.13.25" />
        <vers num="1.13.3" />
        <vers num="1.13.4" />
        <vers num="1.13.5" />
        <vers num="1.13.6" />
        <vers num="1.13.7" />
        <vers num="1.13.8" />
        <vers num="1.13.9" />
        <vers num="1.14.0" />
        <vers num="1.14.1" />
        <vers num="1.14.10" />
        <vers num="1.14.11" />
        <vers num="1.14.12" />
        <vers num="1.14.13" />
        <vers num="1.14.14" />
        <vers num="1.14.15" />
        <vers num="1.14.16" />
        <vers num="1.14.16.1" />
        <vers num="1.14.16.2" />
        <vers num="1.14.16.3" />
        <vers num="1.14.16.4" />
        <vers num="1.14.16.5" />
        <vers num="1.14.16.6" />
        <vers num="1.14.17" />
        <vers num="1.14.18" />
        <vers num="1.14.19" />
        <vers num="1.14.2" />
        <vers num="1.14.20" />
        <vers num="1.14.21" />
        <vers num="1.14.22" />
        <vers num="1.14.23" />
        <vers num="1.14.24" />
        <vers num="1.14.25" />
        <vers num="1.14.26" />
        <vers num="1.14.27" />
        <vers num="1.14.28" />
        <vers num="1.14.29" />
        <vers num="1.14.3" />
        <vers prev="1" num="1.14.30" />
        <vers num="1.14.4" />
        <vers num="1.14.5" />
        <vers num="1.14.6" />
        <vers num="1.14.7" />
        <vers num="1.14.8" />
        <vers num="1.14.9" />
        <vers num="1.15.0" />
        <vers num="1.15.1" />
        <vers num="1.15.2" />
        <vers num="1.15.3" />
        <vers num="1.15.3.1" />
        <vers num="1.15.4" />
        <vers num="1.15.4.1" />
        <vers num="1.15.5" />
        <vers num="1.15.5.1" />
        <vers num="1.15.5.2" />
        <vers num="1.15.5.3" />
        <vers num="1.15.5.4" />
        <vers num="1.15.5.5" />
        <vers num="1.15.5.6" />
        <vers num="1.15.6" />
        <vers num="1.15.6.1" />
        <vers num="1.15.7" />
        <vers num="1.15.7.1" />
        <vers num="1.15.7.2" />
        <vers num="1.15.8" />
        <vers num="1.15.8.1" />
        <vers num="1.15.8.2" />
        <vers num="1.15.8.3" />
        <vers num="1.15.8.4" />
        <vers num="1.15.8.5" />
        <vers num="1.15.8.6" />
        <vers num="1.15.8.7" />
        <vers num="1.15.8.8" />
        <vers num="1.9.19" />
        <vers num="1.9.20" />
        <vers num="1.9.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1680" reject="1" published="2011-12-14" name="CVE-2010-1680" modified="2011-12-14">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-1681" published="2010-05-06" name="CVE-2010-1681" modified="2010-09-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39836" source="BID" patch="1">39836</ref>
      <ref url="http://www.securitytracker.com/id?1023938" source="SECTRACK">1023938</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511121/100/0/threaded" source="BUGTRAQ">20100504 [CORE-2010-0428] Microsoft Office Visio DXF File Insertion Buffer Overflow</ref>
      <ref url="http://www.exploit-db.com/exploits/14944" source="EXPLOIT-DB">14944</ref>
      <ref url="http://www.coresecurity.com/content/ms-visio-dxf-buffer-overflow" source="MISC">http://www.coresecurity.com/content/ms-visio-dxf-buffer-overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1685" published="2010-05-04" name="CVE-2010-1685" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-031-zip-wrangler-1-20-buffer-overflow/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-031-zip-wrangler-1-20-buffer-overflow/</ref>
      <ref url="http://secunia.com/advisories/39575" source="SECUNIA" adv="1">39575</ref>
      <ref url="http://osvdb.org/64079" source="OSVDB">64079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cursorarts" name="zipwrangler">
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1686" published="2010-05-05" name="CVE-2010-1686" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1047" source="VUPEN" adv="1">ADV-2010-1047</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1046" source="VUPEN" adv="1">ADV-2010-1046</ref>
      <ref url="http://www.corelan.be:8800/advisories.php?id=CORELAN-10-034" source="MISC">http://www.corelan.be:8800/advisories.php?id=CORELAN-10-034</ref>
      <ref url="http://secunia.com/advisories/39701" source="SECUNIA" adv="1">39701</ref>
      <ref url="http://secunia.com/advisories/39699" source="SECUNIA" adv="1">39699</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abcbackup" name="abc_backup">
        <vers num="5.20" edition="-" />
        <vers num="5.20" edition="-:pro" />
        <vers num="5.50" />
      </prod>
      <prod vendor="internet-soft" name="urgent_backup">
        <vers num="3.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1687" published="2010-05-04" name="CVE-2010-1687" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/63902" source="OSVDB">63902</ref>
      <ref url="http://www.corelan.be:8800/wp-content/forum-file-uploads/mr_me/mochalpd.py_.txt" source="MISC">http://www.corelan.be:8800/wp-content/forum-file-uploads/mr_me/mochalpd.py_.txt</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-023-mocha-lpd-remote-buffer-overflow/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-023-mocha-lpd-remote-buffer-overflow/</ref>
      <ref url="http://secunia.com/advisories/39394" source="SECUNIA" adv="1">39394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mochasoft" name="mocha_w32_lpd">
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1688" published="2010-05-24" name="CVE-2010-1688" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.2brightsparks.com/freeware/changes.html" source="CONFIRM" patch="1">http://www.2brightsparks.com/freeware/changes.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58727" source="XF">syncback-sps-bo(58727)</ref>
      <ref url="http://www.securityfocus.com/bid/40311" source="BID">40311</ref>
      <ref url="http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt" source="MISC">http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt</ref>
      <ref url="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/" source="MISC">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/</ref>
      <ref url="http://secunia.com/advisories/39865" source="SECUNIA" adv="1">39865</ref>
      <ref url="http://osvdb.org/64752" source="OSVDB">64752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2brightsparks" name="syncback">
        <vers num="3.2.20.0" edition="-" />
        <vers num="3.2.20.0" edition="-:freeware" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1689" published="2010-05-07" name="CVE-2010-1689" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39908" source="BID">39908</ref>
      <ref url="http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs" source="MISC">http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs</ref>
      <ref url="http://securitytracker.com/id?1023939" source="SECTRACK">1023939</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html" source="FULLDISC">20100504 [CORE-2010-0427] Windows SMTP Service DNS query Id vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers prev="1" num="2003" edition="sp2" />
        <vers prev="1" num="2003" edition="sp3" />
        <vers prev="1" num="2007" edition="sp1" />
        <vers prev="1" num="2007" edition="sp1:x64" />
        <vers prev="1" num="2007" edition="sp2" />
        <vers prev="1" num="2007" edition="sp2:x64" />
        <vers num="2010" edition="-" />
        <vers num="2010" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers prev="1" num="-" edition="sp2" />
        <vers prev="1" num="-" edition="sp2:x64" />
        <vers prev="1" num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1690" published="2010-05-07" name="CVE-2010-1690" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39910" source="BID" patch="1">39910</ref>
      <ref url="http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs" source="MISC">http://www.coresecurity.com/content/CORE-2010-0424-windows-smtp-dns-query-id-bugs</ref>
      <ref url="http://securitytracker.com/id?1023939" source="SECTRACK">1023939</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0058.html" source="FULLDISC">20100504 [CORE-2010-0427] Windows SMTP Service DNS query Id vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers prev="1" num="2003" edition="sp2" />
        <vers prev="1" num="2003" edition="sp3" />
        <vers prev="1" num="2007" edition="sp1" />
        <vers prev="1" num="2007" edition="sp1:x64" />
        <vers prev="1" num="2007" edition="sp2" />
        <vers prev="1" num="2007" edition="sp2:x64" />
        <vers num="2010" edition="-" />
        <vers num="2010" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers prev="1" num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers prev="1" num="-" edition="sp2" />
        <vers prev="1" num="-" edition="sp2:x64" />
        <vers prev="1" num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers prev="1" num="" edition="sp2" />
        <vers prev="1" num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1693" published="2010-10-26" name="CVE-2010-1693" modified="2010-10-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:C/A:C)" CVSS_score="6.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.4" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/62753" source="XF">ofed-openibd-symlink(62753)</ref>
      <ref url="http://www.securityfocus.com/bid/44332" source="BID">44332</ref>
      <ref url="http://www.osvdb.org/68856" source="OSVDB">68856</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/10/22/1" source="MLIST">[oss-security] 20101022 CVE-2010-1693: OFED openibd startup script uses predictable tmpfile</ref>
      <ref url="http://secunia.com/advisories/41937" source="SECUNIA" adv="1">41937</ref>
      <ref url="http://lists.openfabrics.org/pipermail/ewg/2010-October/015886.html" source="MLIST">[ewg] 20101021 [PATCH] security fix in openibd script</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openfabrics" name="enterprise_distribution">
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1701" published="2010-05-04" name="CVE-2010-1701" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1027" source="VUPEN" adv="1">ADV-2010-1027</ref>
      <ref url="http://www.exploit-db.com/exploits/12444" source="EXPLOIT-DB">12444</ref>
      <ref url="http://secunia.com/advisories/39647" source="SECUNIA" adv="1">39647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rocky.nu" name="php_video_battle_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1702" published="2010-05-04" name="CVE-2010-1702" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58108" source="XF">whmcs-submitticket-sql-injection(58108)</ref>
      <ref url="http://www.securityfocus.com/bid/39681" source="BID">39681</ref>
      <ref url="http://www.exploit-db.com/exploits/12371" source="EXPLOIT-DB">12371</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/whmcs-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/whmcs-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="whmcs" name="whmcs">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1703" published="2010-05-04" name="CVE-2010-1703" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58190" source="XF">polls-indexsearch-xss(58190)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58128" source="XF">aps-category-xss(58128)</ref>
      <ref url="http://www.securityfocus.com/bid/39745" source="BID">39745</ref>
      <ref url="http://www.exploit-db.com/exploits/12395" source="EXPLOIT-DB">12395</ref>
      <ref url="http://secunia.com/advisories/39622" source="SECUNIA" adv="1">39622</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/aps-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/aps-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="polls_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1704" published="2010-05-04" name="CVE-2010-1704" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password field (aka pass parameter) to the default URI under admin/, and possibly (4) the login field to the default URI under admin/.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58189" source="XF">polls-login-sql-injection(58189)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58127" source="XF">aps-login-sql-injection(58127)</ref>
      <ref url="http://www.securityfocus.com/bid/39745" source="BID">39745</ref>
      <ref url="http://www.exploit-db.com/exploits/12395" source="EXPLOIT-DB">12395</ref>
      <ref url="http://secunia.com/advisories/39622" source="SECUNIA" adv="1">39622</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/aps-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/aps-sqlxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="polls_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1705" published="2010-05-04" name="CVE-2010-1705" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1028" source="VUPEN" adv="1">ADV-2010-1028</ref>
      <ref url="http://www.exploit-db.com/exploits/12443" source="EXPLOIT-DB">12443</ref>
      <ref url="http://secunia.com/advisories/39646" source="SECUNIA" adv="1">39646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rocky.nu" name="modelbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1706" published="2010-05-04" name="CVE-2010-1706" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58188" source="XF">2daybiz-login-sql-injection(58188)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1015" source="VUPEN" adv="1">ADV-2010-1015</ref>
      <ref url="http://www.securityfocus.com/bid/39728" source="BID">39728</ref>
      <ref url="http://www.exploit-db.com/exploits/12414" source="EXPLOIT-DB">12414</ref>
      <ref url="http://secunia.com/advisories/39621" source="SECUNIA" adv="1">39621</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/2daybizauctionscript-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/2daybizauctionscript-sql.txt</ref>
      <ref url="http://osvdb.org/64097" source="OSVDB">64097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="auction_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1707" published="2010-05-04" name="CVE-2010-1707" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1034" source="VUPEN" patch="1" adv="1">ADV-2010-1034</ref>
      <ref url="http://piwigo.org/code/wsvn/Piwigo?op=revision&amp;rev=5936" source="CONFIRM" patch="1">http://piwigo.org/code/wsvn/Piwigo?op=revision&amp;rev=5936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="piwigo" name="piwigo">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers prev="1" num="2.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1708" published="2010-05-04" name="CVE-2010-1708" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58193" source="XF">freerealty-agentadmin-sql-injection(58193)</ref>
      <ref url="http://www.securityfocus.com/bid/39712" source="BID">39712</ref>
      <ref url="http://www.exploit-db.com/exploits/12411" source="EXPLOIT-DB">12411</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/freerealty-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/freerealty-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freerealty.rwcinc" name="free_realty">
        <vers num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.7" edition="pre1" />
        <vers num="2.7" edition="pre2" />
        <vers num="2.7" edition="pre3" />
        <vers num="2.7" edition="pre4" />
        <vers num="2.7" edition="pre5" />
        <vers num="2.7" edition="pre6" />
        <vers num="2.7" edition="pre7" />
        <vers num="2.8" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.8.5" />
        <vers num="2.8.6" edition="pre1" />
        <vers num="2.8.6" edition="pre2" />
        <vers num="2.8.6" edition="pre3" />
        <vers num="2.8.6-1" />
        <vers num="2.9" edition="pre1" />
        <vers num="2.9" edition="pre2" />
        <vers num="2.9" edition="pre2.1" />
        <vers num="2.9" edition="pre2.2" />
        <vers num="2.9" edition="pre3.0" />
        <vers num="2.9-0.0" />
        <vers num="2.9-0.1" />
        <vers num="2.9-0.2" />
        <vers num="2.9-0.3" />
        <vers num="2.9-0.4" />
        <vers num="2.9-0.5" />
        <vers num="2.9-0.7" />
        <vers num="2.9-0.7.1" />
        <vers num="2.9-0.7.2" />
        <vers num="2.9-0.7.3" />
        <vers num="2.9-0.7.4" />
        <vers num="3.0-0" edition="rc1" />
        <vers num="3.0-0" edition="rc2" />
        <vers num="3.0-0" edition="rc3" />
        <vers num="3.0-0" edition="rc4" />
        <vers num="3.0-0" edition="rc5" />
        <vers num="3.0-0" edition="rc6" />
        <vers num="3.0-0" edition="rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1709" published="2010-05-04" name="CVE-2010-1709" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pass parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58139" source="XF">aig-upload-xss(58139)</ref>
      <ref url="http://www.xenuser.org/documents/security/auto-img-gallery_xss.txt" source="MISC">http://www.xenuser.org/documents/security/auto-img-gallery_xss.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39714" source="BID">39714</ref>
      <ref url="http://secunia.com/advisories/39599" source="SECUNIA" adv="1">39599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="g5-scripts" name="auto-img-gallery">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1710" published="2010-05-04" name="CVE-2010-1710" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57900" source="XF">siestta-login-file-include(57900)</ref>
      <ref url="http://www.securityfocus.com/bid/39526" source="BID">39526</ref>
      <ref url="http://www.osvdb.org/63837" source="OSVDB">63837</ref>
      <ref url="http://www.exploit-db.com/exploits/12260" source="EXPLOIT-DB">12260</ref>
      <ref url="http://secunia.com/advisories/39453" source="SECUNIA" adv="1">39453</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/siestta-lfixss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/siestta-lfixss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ramoncastro" name="siestta">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1711" published="2010-05-04" name="CVE-2010-1711" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57899" source="XF">siestta-usuario-xss(57899)</ref>
      <ref url="http://www.securityfocus.com/bid/39526" source="BID">39526</ref>
      <ref url="http://www.osvdb.org/63836" source="OSVDB">63836</ref>
      <ref url="http://www.exploit-db.com/exploits/12260" source="EXPLOIT-DB">12260</ref>
      <ref url="http://secunia.com/advisories/39453" source="SECUNIA" adv="1">39453</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/siestta-lfixss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/siestta-lfixss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ramoncastro" name="siestta">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1712" published="2010-05-04" name="CVE-2010-1712" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58025" source="XF">wbnews-comments-xss(58025)</ref>
      <ref url="http://www.securityfocus.com/bid/39626" source="BID">39626</ref>
      <ref url="http://www.osvdb.org/63973" source="OSVDB">63973</ref>
      <ref url="http://www.itsecteam.com/en/vulnerabilities/vulnerability44.htm" source="MISC">http://www.itsecteam.com/en/vulnerabilities/vulnerability44.htm</ref>
      <ref url="http://www.hack0wn.com/view.php?xroot=1310.0&amp;cat=exploits" source="MISC">http://www.hack0wn.com/view.php?xroot=1310.0&amp;cat=exploits</ref>
      <ref url="http://www.exploit-db.com/exploits/12323" source="EXPLOIT-DB">12323</ref>
      <ref url="http://secunia.com/advisories/39516" source="SECUNIA" adv="1">39516</ref>
      <ref url="http://inj3ct0r.com/exploits/11914" source="MISC">http://inj3ct0r.com/exploits/11914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers num="2.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1713" published="2010-05-04" name="CVE-2010-1713" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58204" source="XF">modload-index-sql-injection(58204)</ref>
      <ref url="http://www.securityfocus.com/bid/39713" source="BID">39713</ref>
      <ref url="http://www.exploit-db.com/exploits/12410" source="EXPLOIT-DB">12410</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/postnukemodload-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/postnukemodload-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postnuke" name="postnuke">
        <vers num="0.764" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1714" published="2010-05-04" name="CVE-2010-1714" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57683" source="XF">comarcadegames-controller-file-include(57683)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0860" source="VUPEN" adv="1">ADV-2010-0860</ref>
      <ref url="http://www.osvdb.org/63660" source="OSVDB">63660</ref>
      <ref url="http://www.exploit-db.com/exploits/12168" source="EXPLOIT-DB">12168</ref>
      <ref url="http://secunia.com/advisories/39413" source="SECUNIA" adv="1">39413</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaarcadegames-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaarcadegames-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev.pucit.edu.pk" name="com_arcadegames">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1715" published="2010-05-04" name="CVE-2010-1715" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57677" source="XF">comonlineexam-controller-file-include(57677)</ref>
      <ref url="http://www.osvdb.org/63659" source="OSVDB">63659</ref>
      <ref url="http://www.exploit-db.com/exploits/12174" source="EXPLOIT-DB">12174</ref>
      <ref url="http://secunia.com/advisories/39414" source="SECUNIA" adv="1">39414</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaonlineexam-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaonlineexam-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pucit.edu" name="com_onlineexam">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1716" published="2010-05-04" name="CVE-2010-1716" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57770" source="XF">agenda-index-sql-injection(57770)</ref>
      <ref url="http://www.securityfocus.com/bid/39380" source="BID">39380</ref>
      <ref url="http://www.osvdb.org/63723" source="OSVDB">63723</ref>
      <ref url="http://www.joomlanetprojects.com/index.php/en/joomla-projects-downloads/joomla-1/joomla-1/42-comagenda.html" source="MISC">http://www.joomlanetprojects.com/index.php/en/joomla-projects-downloads/joomla-1/joomla-1/42-comagenda.html</ref>
      <ref url="http://www.exploit-db.com/exploits/12132" source="EXPLOIT-DB">12132</ref>
      <ref url="http://secunia.com/advisories/39238" source="SECUNIA" adv="1">39238</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlanetprojects" name="com_agenda">
        <vers num="1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1717" published="2010-05-04" name="CVE-2010-1717" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0924" source="VUPEN" adv="1">ADV-2010-0924</ref>
      <ref url="http://www.exploit-db.com/exploits/12291" source="EXPLOIT-DB">12291</ref>
      <ref url="http://secunia.com/advisories/39526" source="SECUNIA" adv="1">39526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inertialfate" name="com_if_surfalert">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1718" published="2010-05-04" name="CVE-2010-1718" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39545" source="BID">39545</ref>
      <ref url="http://www.exploit-db.com/exploits/12282" source="EXPLOIT-DB">12282</ref>
      <ref url="http://secunia.com/advisories/39521" source="SECUNIA" adv="1">39521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lispeltuut" name="com_archeryscores">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1719" published="2010-05-04" name="CVE-2010-1719" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57850" source="XF">commtfireeagle-index-file-inlclude(57850)</ref>
      <ref url="http://www.securityfocus.com/bid/39509" source="BID">39509</ref>
      <ref url="http://www.exploit-db.com/exploits/12233" source="EXPLOIT-DB">12233</ref>
      <ref url="http://secunia.com/advisories/39470" source="SECUNIA" adv="1">39470</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlamtfireeagle-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlamtfireeagle-lfi.txt</ref>
      <ref url="http://osvdb.org/63806" source="OSVDB">63806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moto-treks" name="com_mtfireeagle">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1720" published="2010-05-04" name="CVE-2010-1720" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57775" source="XF">qpersonel-index-sql-injection(57775)</ref>
      <ref url="http://www.xenuser.org/documents/security/qpersonel_sql.txt" source="MISC">http://www.xenuser.org/documents/security/qpersonel_sql.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39466" source="BID">39466</ref>
      <ref url="http://www.exploit-db.com/exploits/12200" source="EXPLOIT-DB">12200</ref>
      <ref url="http://secunia.com/advisories/39445" source="SECUNIA" adv="1">39445</ref>
      <ref url="http://osvdb.org/63894" source="OSVDB">63894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qproje" name="com_qpersonel">
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1721" published="2010-05-04" name="CVE-2010-1721" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57875" source="XF">intellectual-index-sql-injection(57875)</ref>
      <ref url="http://www.securityfocus.com/bid/39495" source="BID">39495</ref>
      <ref url="http://www.exploit-db.com/exploits/12246" source="EXPLOIT-DB">12246</ref>
      <ref url="http://secunia.com/advisories/39427" source="SECUNIA" adv="1">39427</ref>
      <ref url="http://osvdb.org/63750" source="OSVDB">63750</ref>
      <ref url="http://extensions.thethinkery.net/" source="MISC">http://extensions.thethinkery.net/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thethinkery" name="com_iproperty">
        <vers num="1.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1722" published="2010-05-04" name="CVE-2010-1722" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57674" source="XF">commarket-controller-file-include(57674)</ref>
      <ref url="http://www.osvdb.org/63671" source="OSVDB">63671</ref>
      <ref url="http://www.exploit-db.com/exploits/12177" source="EXPLOIT-DB">12177</ref>
      <ref url="http://secunia.com/advisories/39409" source="SECUNIA" adv="1">39409</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaonlinemarket-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaonlinemarket-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dev.pucit.edu.pk" name="com_market">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1723" published="2010-05-04" name="CVE-2010-1723" modified="2010-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0926" source="VUPEN" adv="1">ADV-2010-0926</ref>
      <ref url="http://www.exploit-db.com/exploits/12289" source="EXPLOIT-DB">12289</ref>
      <ref url="http://secunia.com/advisories/39524" source="SECUNIA" adv="1">39524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlacomponent.inetlanka" name="com_drawroot">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1724" published="2010-05-06" name="CVE-2010-1724" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58224" source="XF">zikula-index-xss(58224)</ref>
      <ref url="http://www.securityfocus.com/bid/39717" source="BID">39717</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510988/100/0/threaded" source="BUGTRAQ">20100427 XSS vulnerability in Zikula Application Framework</ref>
      <ref url="http://www.osvdb.org/64095" source="OSVDB">64095</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework_1.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework_1.html</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework.html</ref>
      <ref url="http://secunia.com/advisories/39614" source="SECUNIA" adv="1">39614</ref>
      <ref url="http://osvdb.org/64096" source="OSVDB">64096</ref>
      <ref url="http://community.zikula.org/index.php?module=News&amp;func=display&amp;sid=3012&amp;title=zikula-1.2.3-release-announcement" source="CONFIRM" adv="1">http://community.zikula.org/index.php?module=News&amp;func=display&amp;sid=3012&amp;title=zikula-1.2.3-release-announcement</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zikula" name="zikula_application_framework">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1725" published="2010-05-06" name="CVE-2010-1725" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58262" source="XF">alibabacloneplatinum-id-sql-injection(58262)</ref>
      <ref url="http://www.securityfocus.com/bid/39846" source="BID">39846</ref>
      <ref url="http://www.exploit-db.com/exploits/12468" source="EXPLOIT-DB">12468</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/alibabacloneplatinum-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/alibabacloneplatinum-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alibabaclone" name="alibaba_clone_platinum">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1726" published="2010-05-06" name="CVE-2010-1726" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58266" source="XF">ec21-offersbuyout-sql-injection(58266)</ref>
      <ref url="http://www.securityfocus.com/bid/39832" source="BID">39832</ref>
      <ref url="http://www.exploit-db.com/exploits/12459" source="EXPLOIT-DB">12459</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/ec21clone-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/ec21clone-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alibabaclone" name="ec21_clone">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1727" published="2010-05-06" name="CVE-2010-1727" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58264" source="XF">jobpost-type-sql-injection(58264)</ref>
      <ref url="http://www.securityfocus.com/bid/39831" source="BID">39831</ref>
      <ref url="http://www.exploit-db.com/exploits/12461" source="EXPLOIT-DB">12461</ref>
      <ref url="http://secunia.com/advisories/39708" source="SECUNIA" adv="1">39708</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/jobpost-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/jobpost-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspsiteware" name="jobpost">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1728" published="2010-05-06" name="CVE-2010-1728" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via JavaScript that writes &lt;marquee> sequences in an infinite loop, leading to attempted use of uninitialized memory.  NOTE: this might overlap CVE-2006-6955.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58231" source="XF">opera-documentwrite-code-execution(58231)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0999" source="VUPEN" adv="1">ADV-2010-0999</ref>
      <ref url="http://www.opera.com/support/kb/view/953/" source="CONFIRM" adv="1">http://www.opera.com/support/kb/view/953/</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/1053/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/1053/</ref>
      <ref url="http://www.opera.com/docs/changelogs/mac/1053/" source="CONFIRM">http://www.opera.com/docs/changelogs/mac/1053/</ref>
      <ref url="http://secunia.com/advisories/39590" source="SECUNIA" adv="1">39590</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11927" source="OVAL">oval:org.mitre.oval:def:11927</ref>
      <ref url="http://my.opera.com/desktopteam/blog/2010/04/28/opera-10-53-rc1-for-windows-and-mac" source="CONFIRM">http://my.opera.com/desktopteam/blog/2010/04/28/opera-10-53-rc1-for-windows-and-mac</ref>
      <ref url="http://h.ackack.net/?p=258" source="MISC">http://h.ackack.net/?p=258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="10.00" edition="beta1" />
        <vers num="10.00" edition="beta2" />
        <vers num="10.00" edition="beta3" />
        <vers num="10.01" />
        <vers num="10.10" edition="beta1" />
        <vers num="10.50" edition="beta1" />
        <vers num="10.50" edition="beta2" />
        <vers num="10.51" />
        <vers prev="1" num="10.52" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="beta3" />
        <vers num="5.0" edition="beta4" />
        <vers num="5.0" edition="beta5" />
        <vers num="5.0" edition="beta6" />
        <vers num="5.0" edition="beta7" />
        <vers num="5.0" edition="beta8" />
        <vers num="5.02" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="tp1" />
        <vers num="6.0" edition="tp2" />
        <vers num="6.0" edition="tp3" />
        <vers num="6.01" />
        <vers num="6.02" />
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="6.05" />
        <vers num="6.06" />
        <vers num="6.1" edition="beta1" />
        <vers num="6.11" />
        <vers num="6.12" />
        <vers num="7.0" edition="beta1" />
        <vers num="7.0" edition="beta1_v2" />
        <vers num="7.0" edition="beta2" />
        <vers num="7.01" />
        <vers num="7.02" />
        <vers num="7.03" />
        <vers num="7.10" edition="beta1" />
        <vers num="7.11" edition="beta2" />
        <vers num="7.20" edition="beta7" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.50" edition="beta1" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" edition="update1" />
        <vers num="7.54" edition="update2" />
        <vers num="7.60" />
        <vers num="8.0" edition="beta2" />
        <vers num="8.00" />
        <vers num="8.01" />
        <vers num="8.50" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.54" />
        <vers num="9.0" edition="beta2" />
        <vers num="9.00" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.20" edition="beta1" />
        <vers num="9.22" />
        <vers num="9.24" />
        <vers num="9.25" />
        <vers num="9.26" />
        <vers num="9.27" />
        <vers num="9.50" edition="beta1" />
        <vers num="9.50" edition="beta2" />
        <vers num="9.51" />
        <vers num="9.52" />
        <vers num="9.60" edition="beta1" />
        <vers num="9.61" />
        <vers num="9.63" />
        <vers num="9.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1729" published="2010-05-06" name="CVE-2010-1729" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes &lt;marquee> sequences in an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://h.ackack.net/?p=258" source="MISC">http://h.ackack.net/?p=258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1730" published="2010-05-06" name="CVE-2010-1730" modified="2010-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes &lt;marquee> sequences in an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://h.ackack.net/?p=258" source="MISC">http://h.ackack.net/?p=258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dolphin" name="dolphin_browser">
        <vers num="2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1731" published="2010-05-06" name="CVE-2010-1731" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes &lt;marquee> sequences in an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://h.ackack.net/?p=258" source="MISC">http://h.ackack.net/?p=258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1732" published="2010-05-06" name="CVE-2010-1732" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack the authentication of administrators for requests that change the administrator email address (updateemail action).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.htbridge.ch/advisory/xsrf_csrf_in_zikula_application_framework.html" source="MISC">http://www.htbridge.ch/advisory/xsrf_csrf_in_zikula_application_framework.html</ref>
      <ref url="http://community.zikula.org/index.php?module=News&amp;func=display&amp;sid=3012&amp;title=zikula-1.2.3-release-announcement" source="CONFIRM">http://community.zikula.org/index.php?module=News&amp;func=display&amp;sid=3012&amp;title=zikula-1.2.3-release-announcement</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zikula" name="zikula_application_framework">
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1733" published="2010-05-06" name="CVE-2010-1733" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55873" source="XF">ocsinventoryng-searchform-sql-injection(55873)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:178" source="MANDRIVA">MDVSA-2010:178</ref>
      <ref url="http://secunia.com/advisories/38311" source="SECUNIA" adv="1">38311</ref>
      <ref url="http://osvdb.org/61942" source="OSVDB">61942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.0" edition="rc3-1" />
        <vers num="1.01" />
        <vers num="1.02" edition="" />
        <vers num="1.02" edition=":unix" />
        <vers num="1.02" edition="rc1" />
        <vers num="1.02" edition="rc2" />
        <vers num="1.02" edition="rc3" />
        <vers prev="1" num="1.02.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1734" published="2010-05-06" name="CVE-2010-1734" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39631" source="BID">39631</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510886/100/0/threaded" source="BUGTRAQ">20100422 Windows 2000/XP/2003 win32k.sys SfnINSTRING local kernel Denial of Service Vulnerability</ref>
      <ref url="http://vigilance.fr/vulnerability/Windows-denials-of-service-of-win32k-sys-9607" source="MISC">http://vigilance.fr/vulnerability/Windows-denials-of-service-of-win32k-sys-9607</ref>
      <ref url="http://secunia.com/advisories/39456" source="SECUNIA" adv="1">39456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="beta3" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="gold:advanced_server" />
        <vers num="" edition="gold:server" />
        <vers num="" edition="gold:datacenter_server" />
        <vers num="" edition="rc1" />
        <vers num="" edition="rc2" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
        <vers num="beta3" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:datacenter" />
        <vers num="" edition="gold:compute_cluster" />
        <vers num="" edition="gold:x64-standard" />
        <vers num="" edition="gold:storage" />
        <vers num="" edition="gold:enterprise" />
        <vers num="" edition="gold:itanium" />
        <vers num="" edition="gold:x64" />
        <vers num="" edition="gold:standard" />
        <vers num="" edition="gold:x64-enterprise" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:storage" />
        <vers num="" edition="r2:datacenter" />
        <vers num="" edition="r2:enterprise" />
        <vers num="" edition="r2:standard" />
        <vers num="" edition="r2:x64-standard" />
        <vers num="" edition="r2:x64-enterprise" />
        <vers num="" edition="r2:compute_cluster" />
        <vers num="" edition="r2:x64-datacenter" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter" />
        <vers num="" edition="sp1:storage" />
        <vers num="" edition="sp1:compute_cluster" />
        <vers num="" edition="sp1:standard" />
        <vers num="" edition="sp1:enterprise" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter" />
        <vers num="" edition="sp2:compute_cluster" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:standard" />
        <vers num="" edition="sp2:storage" />
        <vers num="" edition="sp2:enterprise" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x86" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="gold:tablet_pc" />
        <vers num="" edition="gold:media_center" />
        <vers num="" edition="gold:embedded" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x86" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:embedded" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:x86" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:x64" />
        <vers num="-" edition="gold:64-bit-2003" />
        <vers num="-" edition="gold:64-bit-2002" />
        <vers num="-" edition="gold:home" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp1:home" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:home" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp3" />
        <vers num="-" edition="sp3:tablet_pc" />
        <vers num="-" edition="sp3:home" />
        <vers num="-" edition="sp3:embedded" />
        <vers num="-" edition="sp3:media_center" />
        <vers num="-" edition="sp3:professional" />
        <vers num="sp2" />
        <vers num="sp3" edition="unknown" />
        <vers num="sp3" edition="unknown:english" />
        <vers num="unknown" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1735" published="2010-05-06" name="CVE-2010-1735" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39630" source="BID">39630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510884/100/0/threaded" source="BUGTRAQ">20100422 Windows 2000/XP/2003 win32k.sys SfnLOGONNOTIFY local kernel Denial of Service Vulnerability</ref>
      <ref url="http://vigilance.fr/vulnerability/Windows-denials-of-service-of-win32k-sys-9607" source="MISC">http://vigilance.fr/vulnerability/Windows-denials-of-service-of-win32k-sys-9607</ref>
      <ref url="http://secunia.com/advisories/39456" source="SECUNIA" adv="1">39456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="beta3" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="gold:advanced_server" />
        <vers num="" edition="gold:server" />
        <vers num="" edition="gold:datacenter_server" />
        <vers num="" edition="rc1" />
        <vers num="" edition="rc2" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter_server" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:server" />
        <vers num="" edition="sp1:advanced_server" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:advanced_server" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:datacenter_server" />
        <vers num="" edition="sp2:server" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:datacenter_server" />
        <vers num="" edition="sp3:server" />
        <vers num="" edition="sp3:professional" />
        <vers num="" edition="sp3:advanced_server" />
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:datacenter_server" />
        <vers num="" edition="sp4:server" />
        <vers num="" edition="sp4:professional" />
        <vers num="" edition="sp4:advanced_server" />
        <vers num="beta3" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="gold" />
        <vers num="" edition="gold:datacenter" />
        <vers num="" edition="gold:compute_cluster" />
        <vers num="" edition="gold:x64-standard" />
        <vers num="" edition="gold:storage" />
        <vers num="" edition="gold:enterprise" />
        <vers num="" edition="gold:itanium" />
        <vers num="" edition="gold:x64" />
        <vers num="" edition="gold:standard" />
        <vers num="" edition="gold:x64-enterprise" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:storage" />
        <vers num="" edition="r2:datacenter" />
        <vers num="" edition="r2:enterprise" />
        <vers num="" edition="r2:standard" />
        <vers num="" edition="r2:x64-standard" />
        <vers num="" edition="r2:x64-enterprise" />
        <vers num="" edition="r2:compute_cluster" />
        <vers num="" edition="r2:x64-datacenter" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:datacenter" />
        <vers num="" edition="sp1:storage" />
        <vers num="" edition="sp1:compute_cluster" />
        <vers num="" edition="sp1:standard" />
        <vers num="" edition="sp1:enterprise" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:datacenter" />
        <vers num="" edition="sp2:compute_cluster" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:standard" />
        <vers num="" edition="sp2:storage" />
        <vers num="" edition="sp2:enterprise" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x86" />
        <vers num="" edition="gold" />
        <vers num="" edition="gold:professional" />
        <vers num="" edition="gold:tablet_pc" />
        <vers num="" edition="gold:media_center" />
        <vers num="" edition="gold:embedded" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:media_center" />
        <vers num="" edition="sp1:professional" />
        <vers num="" edition="sp1:tablet_pc" />
        <vers num="" edition="sp1:embedded" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x86" />
        <vers num="" edition="sp2:tablet_pc" />
        <vers num="" edition="sp2:professional" />
        <vers num="" edition="sp2:embedded" />
        <vers num="" edition="sp2:media_center" />
        <vers num="" edition="sp3" />
        <vers num="" edition="sp3:x86" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:x64" />
        <vers num="-" edition="gold:64-bit-2003" />
        <vers num="-" edition="gold:64-bit-2002" />
        <vers num="-" edition="gold:home" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp1:home" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:home" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp3" />
        <vers num="-" edition="sp3:tablet_pc" />
        <vers num="-" edition="sp3:home" />
        <vers num="-" edition="sp3:embedded" />
        <vers num="-" edition="sp3:media_center" />
        <vers num="-" edition="sp3:professional" />
        <vers num="sp2" />
        <vers num="sp3" edition="unknown" />
        <vers num="sp3" edition="unknown:english" />
        <vers num="unknown" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1736" published="2010-05-06" name="CVE-2010-1736" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58284" source="XF">krmhaber-krmdb-information-disclosure(58284)</ref>
      <ref url="http://secunia.com/advisories/39700" source="SECUNIA" adv="1">39700</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/krmhaber-disclose.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/krmhaber-disclose.txt</ref>
      <ref url="http://osvdb.org/64217" source="OSVDB">64217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspindir" name="krm_haber">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1737" published="2010-05-06" name="CVE-2010-1737" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1060" source="VUPEN" adv="1">ADV-2010-1060</ref>
      <ref url="http://www.securityfocus.com/bid/39890" source="BID">39890</ref>
      <ref url="http://www.exploit-db.com/exploits/12488" source="EXPLOIT-DB">12488</ref>
      <ref url="http://secunia.com/advisories/39706" source="SECUNIA" adv="1">39706</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/gallo-rfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/gallo-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carlos_eduardo_sotelo_pinto" name="0.1.0">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1738" reject="1" published="2010-05-06" name="CVE-2010-1738" modified="2010-08-24">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1448.  Reason: This candidate is a duplicate of CVE-2010-1448.  Notes: All CVE users should reference CVE-2010-1448 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2010-1739" published="2010-05-06" name="CVE-2010-1739" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58263" source="XF">comnewsfeeds-feedid-sql-injection(58263)</ref>
      <ref url="http://www.securityfocus.com/bid/39834" source="BID">39834</ref>
      <ref url="http://www.exploit-db.com/exploits/12465" source="EXPLOIT-DB">12465</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlanewsfeeds-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlanewsfeeds-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_newsfeeds">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1740" published="2010-05-06" name="CVE-2010-1740" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58277" source="XF">guppy-newsletter-sql-injection(58277)</ref>
      <ref url="http://www.securityfocus.com/bid/39860" source="BID">39860</ref>
      <ref url="http://www.exploit-db.com/exploits/12484" source="EXPLOIT-DB">12484</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/guppy-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/guppy-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeguppy" name="guppy">
        <vers num="4.5.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1741" published="2010-05-06" name="CVE-2010-1741" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58278" source="XF">billwerx-requestaccount-sql-injection(58278)</ref>
      <ref url="http://www.securityfocus.com/bid/39867" source="BID">39867</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/billwerx-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/billwerx-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="billwerx" name="billwerx_rc">
        <vers num="5.2.2" edition="pl2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1742" published="2010-05-06" name="CVE-2010-1742" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58235" source="XF">scratcher-projects-xss(58235)</ref>
      <ref url="http://www.securityfocus.com/bid/39827" source="BID">39827</ref>
      <ref url="http://www.exploit-db.com/exploits/12458" source="EXPLOIT-DB">12458</ref>
      <ref url="http://secunia.com/advisories/39631" source="SECUNIA" adv="1">39631</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/scratcher-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/scratcher-sqlxss.txt</ref>
      <ref url="http://osvdb.org/64219" source="OSVDB">64219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="satyadeep" name="scratcher">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1743" published="2010-05-06" name="CVE-2010-1743" modified="2010-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58234" source="XF">scratcher-projects-sql-injection(58234)</ref>
      <ref url="http://www.securityfocus.com/bid/39827" source="BID">39827</ref>
      <ref url="http://www.exploit-db.com/exploits/12458" source="EXPLOIT-DB">12458</ref>
      <ref url="http://secunia.com/advisories/39631" source="SECUNIA" adv="1">39631</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/scratcher-sqlxss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/scratcher-sqlxss.txt</ref>
      <ref url="http://osvdb.org/64220" source="OSVDB">64220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="satyadeep" name="scratcher">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1744" published="2010-05-06" name="CVE-2010-1744" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58265" source="XF">b2bgoldscript-id-sql-injection(58265)</ref>
      <ref url="http://www.securityfocus.com/bid/39830" source="BID">39830</ref>
      <ref url="http://www.exploit-db.com/exploits/12460" source="EXPLOIT-DB">12460</ref>
      <ref url="http://secunia.com/advisories/39710" source="SECUNIA" adv="1">39710</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/b2bgoldscript-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/b2bgoldscript-sql.txt</ref>
      <ref url="http://osvdb.org/64212" source="OSVDB">64212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alibabaclone" name="b2b_gold_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1745" reject="1" published="2010-05-06" name="CVE-2010-1745" modified="2010-05-26">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1867.  Reason: This candidate is a duplicate of CVE-2010-1867.  Notes: All CVE users should reference CVE-2010-1867 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1746" published="2010-05-06" name="CVE-2010-1746" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58270" source="XF">tablejx-index-xss(58270)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1053" source="VUPEN" adv="1">ADV-2010-1053</ref>
      <ref url="http://www.securityfocus.com/bid/39854" source="BID">39854</ref>
      <ref url="http://www.exploit-db.com/exploits/12473" source="EXPLOIT-DB">12473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toolsjx" name="com_grid">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1748" published="2010-06-17" name="CVE-2010-1748" modified="2011-06-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstated by the (1) /admin?OP=redirect&amp;URL=% and (2) /admin?URL=/admin/&amp;OP=% URIs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40871" source="BID" patch="1">40871</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0535" source="VUPEN" adv="1">ADV-2011-0535</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN" adv="1">ADV-2010-1481</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:234" source="MANDRIVA">MDVSA-2010:234</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:232" source="MANDRIVA">MDVSA-2010:232</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2176" source="DEBIAN">DSA-2176</ref>
      <ref url="http://secunia.com/advisories/43521" source="SECUNIA" adv="1">43521</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA" adv="1">40220</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9723" source="OVAL">oval:org.mitre.oval:def:9723</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html" source="SUSE">SUSE-SR:2010:023</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://cups.org/str.php?L3577" source="CONFIRM">http://cups.org/str.php?L3577</ref>
      <ref url="http://cups.org/articles.php?L596" source="CONFIRM">http://cups.org/articles.php?L596</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2" edition="b1" />
        <vers num="1.2" edition="b2" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2" edition="rc2" />
        <vers num="1.2" edition="rc3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" edition="b1" />
        <vers num="1.3" edition="rc1" />
        <vers num="1.3" edition="rc2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers prev="1" num="1.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1749" published="2010-06-11" name="CVE-2010-1749" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Cascading Style Sheets (CSS) run-in property and multiple invocations of a destructor for a child element that has been referenced multiple times.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-101" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-101</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511725/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-101: Apple Webkit SVG RadialGradiant Run-in Remote Code Execution Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7180" source="OVAL">oval:org.mitre.oval:def:7180</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1750" published="2010-06-11" name="CVE-2010-1750" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Apple Safari before 5.0 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper window management.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7143" source="OVAL">oval:org.mitre.oval:def:7143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1751" published="2010-06-22" name="CVE-2010-1751" modified="2010-06-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to obtain location information via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html

'Installation note:


These updates are only available through iTunes, and will not appear
in your computer's Software Update application, or in the Apple
Downloads site. Make sure you have an Internet connection and have
installed the latest version of iTunes from www.apple.com/itunes/


iTunes will automatically check Apple's update server on its weekly
schedule. When an update is detected, it will download it. When
the iPhone or iPod touch is docked, iTunes will present the user with
the option to install the update. We recommend applying the update
immediately if possible. Selecting Don't Install will present the
option the next time you connect your iPhone or iPod touch.


The automatic update process may take up to a week depending on the
day that iTunes checks for updates. You may manually obtain the
update via the Check for Updates button within iTunes. After doing
this, the update can be applied when your iPhone or iPod touch is
docked to your computer.


To check that the iPhone or iPod touch has been updated:


* Navigate to Settings
* Select General
* Select About. The version after applying this update will be
"4.0 (8A293)" or later.</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59630" source="XF">appleios-sandbox-info-disclosure(59630)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1752" published="2010-06-22" name="CVE-2010-1752" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to URL handling.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html 

'Installation note: These updates are only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone or iPod touch is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone or iPod touch. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone or iPod touch is docked to your computer. To check that the iPhone or iPod touch has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.0 (8A293)" or later.'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59631" source="XF">appleios-cfnetwork-bo(59631)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1753" published="2010-06-22" name="CVE-2010-1753" modified="2010-06-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG image.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html 

'Installation note: These updates are only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone or iPod touch is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone or iPod touch. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone or iPod touch is docked to your computer. To check that the iPhone or iPod touch has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.0 (8A293)" or later.'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59632" source="XF">appleios-imageio-code-execution(59632)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1754" published="2010-06-22" name="CVE-2010-1754" modified="2010-06-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcode requirements via unspecified vectors.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html 

'Installation note: These updates are only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone or iPod touch is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone or iPod touch. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone or iPod touch is docked to your computer. To check that the iPhone or iPod touch has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.0 (8A293)" or later.'</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59633" source="XF">appleios-passcodelock-security-bypass(59633)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1755" published="2010-06-22" name="CVE-2010-1755" modified="2010-06-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Safari in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the Accept Cookies preference, which makes it easier for remote web servers to track users via a cookie.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html 

'Installation note: These updates are only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone or iPod touch is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone or iPod touch. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone or iPod touch is docked to your computer. To check that the iPhone or iPod touch has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.0 (8A293)" or later.'</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59634" source="XF">appleios-safari-security-bypass(59634)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1756" published="2010-06-22" name="CVE-2010-1756" modified="2010-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The Settings application in Apple iOS before 4 on the iPhone and iPod touch does not properly report the wireless network that is in use, which might make it easier for remote attackers to trick users into communicating over an unintended network.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html 

'Installation note: These updates are only available through iTunes, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes will automatically check Apple's update server on its weekly schedule. When an update is detected, it will download it. When the iPhone or iPod touch is docked, iTunes will present the user with the option to install the update. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iPhone or iPod touch. The automatic update process may take up to a week depending on the day that iTunes checks for updates. You may manually obtain the update via the Check for Updates button within iTunes. After doing this, the update can be applied when your iPhone or iPod touch is docked to your computer. To check that the iPhone or iPod touch has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "4.0 (8A293)" or later.'</sol>
    </sols>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1757" published="2010-06-22" name="CVE-2010-1757" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/41068" source="BID">41068</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers prev="1" num="3.2" edition="-" />
        <vers prev="1" num="3.2" edition="-:ipodtouch" />
        <vers prev="1" num="3.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1758" published="2010-06-11" name="CVE-2010-1758" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving DOM Range objects.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7335" source="OVAL">oval:org.mitre.oval:def:7335</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1759" published="2010-06-11" name="CVE-2010-1759" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7005" source="OVAL">oval:org.mitre.oval:def:7005</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1760" published="2010-08-19" name="CVE-2010-1760" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=37781" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=37781</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/42494" source="BID">42494</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/58409" source="CONFIRM">http://trac.webkit.org/changeset/58409</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1760" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1760</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="r50173" />
        <vers num="r56187" />
        <vers num="r56188" />
        <vers num="r56379" />
        <vers prev="1" num="r58408" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1761" published="2010-06-11" name="CVE-2010-1761" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML document subtrees.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7157" source="OVAL">oval:org.mitre.oval:def:7157</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1762" published="2010-06-11" name="CVE-2010-1762" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML in a TEXTAREA element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7503" source="OVAL">oval:org.mitre.oval:def:7503</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1763" published="2010-06-18" name="CVE-2010-1763" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59507" source="XF">itunes-webkit-unspecified-var2(59507)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://securitytracker.com/id?1024108" source="SECTRACK">1024108</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7221" source="OVAL">oval:org.mitre.oval:def:7221</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" edition="" />
        <vers num="7.6.2" edition=":windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:windows" />
        <vers num="8.0" edition="-" />
        <vers num="8.0" edition="-:windows" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:windows" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:windows" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:windows" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:windows" />
        <vers num="8.1.1" edition="-" />
        <vers num="8.1.1" edition="-:windows" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:windows" />
        <vers num="8.2.1" edition="-" />
        <vers num="8.2.1" edition="-:windows" />
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers num="9.0.3" edition="-" />
        <vers num="9.0.3" edition="-:windows" />
        <vers num="9.1" edition="-" />
        <vers num="9.1" edition="-:windows" />
        <vers prev="1" num="9.1.1" edition="-" />
        <vers prev="1" num="9.1.1" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1764" published="2010-06-11" name="CVE-2010-1764" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, follows multiple redirections during form submission, which allows remote web servers to obtain sensitive information by recording the form data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7347" source="OVAL">oval:org.mitre.oval:def:7347</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1766" published="2010-07-22" name="CVE-2010-1766" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=596494" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=596494</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=36339" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=36339</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1801" source="VUPEN" adv="1">ADV-2010-1801</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/56380" source="CONFIRM">http://trac.webkit.org/changeset/56380</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40557" source="SECUNIA" adv="1">40557</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html" source="FEDORA">FEDORA-2010-11020</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html" source="FEDORA">FEDORA-2010-11011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webkit" name="webkit">
        <vers prev="1" num="r56379" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1767" published="2010-09-24" name="CVE-2010-1767" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=36843" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=36843</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/39603" source="BID">39603</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/57041" source="CONFIRM">http://trac.webkit.org/changeset/57041</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-1767" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-1767</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/39544" source="SECUNIA" adv="1">39544</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11140" source="OVAL">oval:org.mitre.oval:def:11140</ref>
      <ref url="http://osvdb.org/64002" source="OSVDB">64002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=39698" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=39698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers prev="1" num="4.1.249.1058" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1768" published="2010-08-20" name="CVE-2010-1768" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61222" source="XF">itunes-operations-privilege-escalation(61222)</ref>
      <ref url="http://www.securityfocus.com/bid/42538" source="BID">42538</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7604" source="OVAL">oval:org.mitre.oval:def:7604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:mac" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:mac" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:mac" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:mac" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.3" edition="-" />
        <vers num="2.0.3" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0.0" edition="-" />
        <vers num="3.0.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:mac" />
        <vers num="4.0.0" edition="-" />
        <vers num="4.0.0" edition="-:mac" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:mac" />
        <vers num="4.1.0" edition="-" />
        <vers num="4.1.0" edition="-:mac" />
        <vers num="4.2.0" edition="-" />
        <vers num="4.2.0" edition="-:mac" />
        <vers num="4.5.0" edition="-" />
        <vers num="4.5.0" edition="-:mac" />
        <vers num="4.6.0" edition="-" />
        <vers num="4.6.0" edition="-:mac" />
        <vers num="4.7.0" edition="-" />
        <vers num="4.7.0" edition="-:mac" />
        <vers num="4.7.1" edition="-" />
        <vers num="4.7.1" edition="-:mac" />
        <vers num="4.8.0" edition="-" />
        <vers num="4.8.0" edition="-:mac" />
        <vers num="4.9.0" edition="-" />
        <vers num="4.9.0" edition="-:mac" />
        <vers num="5.0.0" edition="-" />
        <vers num="5.0.0" edition="-:mac" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.0.3" edition="-" />
        <vers num="6.0.3" edition="-:mac" />
        <vers num="6.0.4" edition="-" />
        <vers num="6.0.4" edition="-:mac" />
        <vers num="6.0.4.2" edition="-" />
        <vers num="6.0.4.2" edition="-:mac" />
        <vers num="6.0.5" edition="-" />
        <vers num="6.0.5" edition="-:mac" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:mac" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:mac" />
        <vers num="7.4.3" edition="-" />
        <vers num="7.4.3" edition="-:mac" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:mac" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:mac" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:mac" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:mac" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:mac" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:mac" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:mac" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:mac" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:mac" />
        <vers num="8.1.1" edition="-" />
        <vers num="8.1.1" edition="-:mac" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:mac" />
        <vers num="8.2.1" edition="-" />
        <vers num="8.2.1" edition="-:mac" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:mac" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:mac" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:mac" />
        <vers prev="1" num="9.0.3" edition="-" />
        <vers prev="1" num="9.0.3" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1769" published="2010-06-18" name="CVE-2010-1769" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59508" source="XF">itunes-webkit-unspecified-var3(59508)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://securitytracker.com/id?1024108" source="SECTRACK">1024108</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7178" source="OVAL">oval:org.mitre.oval:def:7178</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" edition="" />
        <vers num="7.6.2" edition=":windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:windows" />
        <vers num="8.0" edition="-" />
        <vers num="8.0" edition="-:windows" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:windows" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:windows" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:windows" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:windows" />
        <vers num="8.1.1" edition="-" />
        <vers num="8.1.1" edition="-:windows" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:windows" />
        <vers num="8.2.1" edition="-" />
        <vers num="8.2.1" edition="-:windows" />
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers num="9.0.3" edition="-" />
        <vers num="9.0.3" edition="-:windows" />
        <vers num="9.1" edition="-" />
        <vers num="9.1" edition="-:windows" />
        <vers prev="1" num="9.1.1" edition="-" />
        <vers prev="1" num="9.1.1" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1770" published="2010-06-11" name="CVE-2010-1770" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-10-093/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-10-093/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN" adv="1">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN" adv="1">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN" adv="1">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA" adv="1">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA" adv="1">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA" adv="1">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://secunia.com/advisories/40072" source="SECUNIA" adv="1">40072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7099" source="OVAL">oval:org.mitre.oval:def:7099</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-06-16-1</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=43487" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=43487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers prev="1" num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1771" published="2010-06-11" name="CVE-2010-1771" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving fonts.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59214" source="XF">safari-webkit-fonts-ce(59214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6862" source="OVAL">oval:org.mitre.oval:def:6862</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1772" published="2010-09-24" name="CVE-2010-1772" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=596498" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=596498</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=39388" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=39388</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1801" source="VUPEN" adv="1">ADV-2010-1801</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/59859" source="CONFIRM">http://trac.webkit.org/changeset/59859</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40557" source="SECUNIA" adv="1">40557</ref>
      <ref url="http://secunia.com/advisories/40072" source="SECUNIA" adv="1">40072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11661" source="OVAL">oval:org.mitre.oval:def:11661</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html" source="FEDORA">FEDORA-2010-11020</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html" source="FEDORA">FEDORA-2010-11011</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=44868" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=44868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers prev="1" num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1773" published="2010-09-24" name="CVE-2010-1773" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=596500" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=596500</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=39508" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=39508</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1801" source="VUPEN" adv="1">ADV-2010-1801</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/41575" source="BID">41575</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://trac.webkit.org/changeset/59950" source="CONFIRM">http://trac.webkit.org/changeset/59950</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40557" source="SECUNIA" adv="1">40557</ref>
      <ref url="http://secunia.com/advisories/40072" source="SECUNIA" adv="1">40072</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11830" source="OVAL">oval:org.mitre.oval:def:11830</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html" source="FEDORA">FEDORA-2010-11020</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html" source="FEDORA">FEDORA-2010-11011</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=44955" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=44955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers prev="1" num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1774" published="2010-06-11" name="CVE-2010-1774" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses out-of-bounds memory during processing of HTML tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN" patch="1" adv="1">ADV-2010-1373</ref>
      <ref url="http://www.securityfocus.com/bid/40620" source="BID" patch="1">40620</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59218" source="XF">safari-webkit-htmltables-ce(59218)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://securitytracker.com/id?1024067" source="SECTRACK">1024067</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA" adv="1">40105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7476" source="OVAL">oval:org.mitre.oval:def:7476</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.0.5" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1775" published="2010-06-22" name="CVE-2010-1775" modified="2010-06-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59637" source="XF">appleios-passcode-lock-sec-bypass(59637)</ref>
      <ref url="http://www.securityfocus.com/bid/41016" source="BID">41016</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.1" />
        <vers num="2.2.1" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers prev="1" num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1777" published="2010-07-30" name="CVE-2010-1777" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4263" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4263</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6988" source="OVAL">oval:org.mitre.oval:def:6988</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-07-19-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.1.0" />
        <vers num="4.2.0" />
        <vers num="4.2.72" />
        <vers num="4.5.0" />
        <vers num="4.6.0" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.1.30" />
        <vers num="4.7.2" />
        <vers num="4.8.0" />
        <vers num="4.9.0" />
        <vers num="5.0.0" />
        <vers num="5.0.1" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.4.2" />
        <vers num="6.0.5" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.2.0" />
        <vers num="7.3.0" />
        <vers num="7.3.1" />
        <vers num="7.3.2" />
        <vers num="7.4.0" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.4.3" />
        <vers num="7.5.0" />
        <vers num="7.6.0" />
        <vers num="7.6.1" />
        <vers num="7.6.2" />
        <vers num="7.7.0" />
        <vers num="7.7.1" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.2.20" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="9.0.0" />
        <vers num="9.0.1" />
        <vers num="9.0.2" />
        <vers num="9.0.3" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers prev="1" num="9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1778" published="2010-07-30" name="CVE-2010-1778" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via an RSS feed.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11639" source="OVAL">oval:org.mitre.oval:def:11639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1780" published="2010-07-30" name="CVE-2010-1780" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to element focus.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10964" source="OVAL">oval:org.mitre.oval:def:10964</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1781" published="2010-09-09" name="CVE-2010-1781" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61698" source="XF">appleios-inline-elements-code-exec(61698)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/43077" source="BID">43077</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1782" published="2010-07-30" name="CVE-2010-1782" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to the rendering of an inline element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11935" source="OVAL">oval:org.mitre.oval:def:11935</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1783" published="2010-07-30" name="CVE-2010-1783" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11820" source="OVAL">oval:org.mitre.oval:def:11820</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1784" published="2010-07-30" name="CVE-2010-1784" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The counters functionality in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11766" source="OVAL">oval:org.mitre.oval:def:11766</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1785" published="2010-07-30" name="CVE-2010-1785" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; accesses uninitialized memory during processing of the (1) :first-letter and (2) :first-line pseudo-elements in an SVG text element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11941" source="OVAL">oval:org.mitre.oval:def:11941</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1786" published="2010-07-30" name="CVE-2010-1786" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a foreignObject element in an SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11837" source="OVAL">oval:org.mitre.oval:def:11837</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1787" published="2010-07-30" name="CVE-2010-1787" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a floating element in an SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11877" source="OVAL">oval:org.mitre.oval:def:11877</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1788" published="2010-07-30" name="CVE-2010-1788" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a use element in an SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11962" source="OVAL">oval:org.mitre.oval:def:11962</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1789" published="2010-07-30" name="CVE-2010-1789" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a JavaScript string object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11524" source="OVAL">oval:org.mitre.oval:def:11524</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1790" published="2010-07-30" name="CVE-2010-1790" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle just-in-time (JIT) compiled JavaScript stubs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to a "reentrancy issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11777" source="OVAL">oval:org.mitre.oval:def:11777</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1791" published="2010-07-30" name="CVE-2010-1791" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a JavaScript array index.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11802" source="OVAL">oval:org.mitre.oval:def:11802</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1792" published="2010-07-30" name="CVE-2010-1792" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11898" source="OVAL">oval:org.mitre.oval:def:11898</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1793" published="2010-07-30" name="CVE-2010-1793" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a (1) font-face or (2) use element in an SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11923" source="OVAL">oval:org.mitre.oval:def:11923</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1794" published="2010-08-02" name="CVE-2010-1794" modified="2010-08-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for Mac OS X 10.6 allows local users to cause a denial of service (panic) via a mount request with a large integer in the pa_socket_namelen field.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512642/100/0/threaded" source="BUGTRAQ" patch="1">20100726 Mac OS X WebDAV kernel extension local denial-of-service</ref>
      <ref url="http://www.securityfocus.com/bid/41958" source="BID">41958</ref>
      <ref url="http://securitytracker.com/id?1024250" source="SECTRACK">1024250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1795" published="2010-08-20" name="CVE-2010-1795" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61223" source="XF">itunes-dll-code-execution(61223)</ref>
      <ref url="http://www.securityfocus.com/bid/42541" source="BID">42541</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/513190/100/0/threaded" source="BUGTRAQ">20100818 ACROS Security: Remote Binary Planting in Apple iTunes for Windows (ASPR #2010-08-18-1)</ref>
      <ref url="http://www.acrossecurity.com/aspr/ASPR-2010-08-18-1-PUB.txt" source="MISC">http://www.acrossecurity.com/aspr/ASPR-2010-08-18-1-PUB.txt</ref>
      <ref url="http://support.apple.com/kb/HT4105" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4105</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7217" source="OVAL">oval:org.mitre.oval:def:7217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:windows" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:windows" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:windows" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:windows" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:windows" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:windows" />
        <vers num="2.0.3" edition="-" />
        <vers num="2.0.3" edition="-:windows" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:windows" />
        <vers num="3.0.0" edition="-" />
        <vers num="3.0.0" edition="-:windows" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="4.0.0" edition="-" />
        <vers num="4.0.0" edition="-:windows" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:windows" />
        <vers num="4.1.0" edition="-" />
        <vers num="4.1.0" edition="-:windows" />
        <vers num="4.2.0" edition="-" />
        <vers num="4.2.0" edition="-:windows" />
        <vers num="4.5.0" edition="-" />
        <vers num="4.5.0" edition="-:windows" />
        <vers num="4.6.0" edition="-" />
        <vers num="4.6.0" edition="-:windows" />
        <vers num="4.7.0" edition="-" />
        <vers num="4.7.0" edition="-:windows" />
        <vers num="4.7.1" edition="-" />
        <vers num="4.7.1" edition="-:windows" />
        <vers num="4.8.0" edition="-" />
        <vers num="4.8.0" edition="-:windows" />
        <vers num="4.9.0" edition="-" />
        <vers num="4.9.0" edition="-:windows" />
        <vers num="5.0.0" edition="-" />
        <vers num="5.0.0" edition="-:windows" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.3" edition="-" />
        <vers num="6.0.3" edition="-:windows" />
        <vers num="6.0.4" edition="-" />
        <vers num="6.0.4" edition="-:windows" />
        <vers num="6.0.4.2" edition="-" />
        <vers num="6.0.4.2" edition="-:windows" />
        <vers num="6.0.5" edition="-" />
        <vers num="6.0.5" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.3" edition="-" />
        <vers num="7.4.3" edition="-:windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:windows" />
        <vers num="8.0" edition="-" />
        <vers num="8.0" edition="-:windows" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:windows" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:windows" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:windows" />
        <vers num="8.1.1" edition="-" />
        <vers num="8.1.1" edition="-:windows" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:windows" />
        <vers num="8.2.1" edition="-" />
        <vers num="8.2.1" edition="-:windows" />
        <vers num="9.0.0" edition="-" />
        <vers num="9.0.0" edition="-:windows" />
        <vers num="9.0.1" edition="-" />
        <vers num="9.0.1" edition="-:windows" />
        <vers num="9.0.2" edition="-" />
        <vers num="9.0.2" edition="-:windows" />
        <vers num="9.0.3" edition="-" />
        <vers num="9.0.3" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1796" published="2010-07-30" name="CVE-2010-1796" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/42020" source="BID" patch="1">42020</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-07-28-1</ref>
      <ref url="http://support.apple.com/kb/HT4276" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11112" source="OVAL">oval:org.mitre.oval:def:11112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers prev="1" num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1797" published="2010-08-16" name="CVE-2010-1797" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=621144" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=621144</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019" source="CONFIRM">https://bugs.launchpad.net/ubuntu/maverick/+source/freetype/+bug/617019</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/60856" source="XF">appleios-pdf-code-execution(60856)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2106" source="VUPEN" adv="1">ADV-2010-2106</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2018" source="VUPEN" adv="1">ADV-2010-2018</ref>
      <ref url="http://www.ubuntu.com/usn/USN-972-1" source="UBUNTU">USN-972-1</ref>
      <ref url="http://www.securityfocus.com/bid/42151" source="BID">42151</ref>
      <ref url="http://www.f-secure.com/weblog/archives/00002002.html" source="MISC">http://www.f-secure.com/weblog/archives/00002002.html</ref>
      <ref url="http://www.exploit-db.com/exploits/14538" source="EXPLOIT-DB">14538</ref>
      <ref url="http://support.apple.com/kb/HT4292" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4292</ref>
      <ref url="http://support.apple.com/kb/HT4291" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4291</ref>
      <ref url="http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/view" source="CONFIRM">http://sourceforge.net/projects/freetype/files/freetype2/2.4.2/NEWS/view</ref>
      <ref url="http://secunia.com/advisories/40982" source="SECUNIA" adv="1">40982</ref>
      <ref url="http://secunia.com/advisories/40816" source="SECUNIA" adv="1">40816</ref>
      <ref url="http://secunia.com/advisories/40807" source="SECUNIA" adv="1">40807</ref>
      <ref url="http://osvdb.org/66828" source="OSVDB">66828</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-08-11-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00000.html" source="APPLE">APPLE-SA-2010-08-11-1</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=11d65e8a1f1f14e56148fd991965424d9bd1cdbc" source="CONFIRM">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=11d65e8a1f1f14e56148fd991965424d9bd1cdbc</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=018f5c27813dd7eef4648fe254632ecea0c85a50" source="CONFIRM">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=018f5c27813dd7eef4648fe254632ecea0c85a50</ref>
      <ref url="http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2" source="CONFIRM">http://freetype.sourceforge.net/index2.html#release-freetype-2.4.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.1.1" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:ipad" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1799" published="2010-08-16" name="CVE-2010-1799" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41962" source="BID">41962</ref>
      <ref url="http://support.apple.com/kb/HT4290" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4290</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11800" source="OVAL">oval:org.mitre.oval:def:11800</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00002.html" source="APPLE">APPLE-SA-2010-08-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="3.0" />
        <vers num="4.1.2" edition="" />
        <vers num="4.1.2" edition=":" />
        <vers num="4.1.2" edition="::japanese" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="" />
        <vers num="7.1.6" edition=":java" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":windows_sp_2" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2" edition=":windows_xp_sp2" />
        <vers num="7.2" edition=":windows_vista" />
        <vers num="7.2" edition=":windows_xp" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" />
        <vers num="7.6.6" edition="-" />
        <vers num="7.6.6" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1800" published="2010-08-25" name="CVE-2010-1800" modified="2010-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://securitytracker.com/id?1024359" source="SECTRACK">1024359</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-08-24-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cfnetwork">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1801" published="2010-08-25" name="CVE-2010-1801" modified="2010-11-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://securitytracker.com/id?1024359" source="SECTRACK">1024359</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-08-24-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="coregraphics">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1802" published="2010-08-25" name="CVE-2010-1802" modified="2010-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://securitytracker.com/id?1024359" source="SECTRACK">1024359</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-08-24-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="libsecurity">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1803" published="2010-11-15" name="CVE-2010-1803" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1804" published="2010-12-21" name="CVE-2010-1804" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4298" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4298</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-12-16-1</ref>
      <ref url="http://www.securitytracker.com/id?1024907" source="SECTRACK">1024907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="airport_express">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="airport_express_base_station_firmware">
        <vers num="3.84" />
        <vers num="4.0.9" />
        <vers num="6.1" />
        <vers num="6.3" />
        <vers num="7.3.2" />
        <vers num="7.4.1" />
        <vers prev="1" num="7.4.2" />
      </prod>
      <prod vendor="apple" name="airport_extreme">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="airport_extreme_base_station_firmware">
        <vers num="5.5" />
        <vers num="5.7" />
      </prod>
      <prod vendor="apple" name="time_capsule">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1805" published="2010-09-10" name="CVE-2010-1805" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/43048" source="BID" patch="1">43048</ref>
      <ref url="http://support.apple.com/kb/HT4333" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11956" source="OVAL">oval:org.mitre.oval:def:11956</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-09-07-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1806" published="2010-09-10" name="CVE-2010-1806" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/43049" source="BID" patch="1">43049</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4333" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4333</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11729" source="OVAL">oval:org.mitre.oval:def:11729</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-09-07-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1807" published="2010-09-10" name="CVE-2010-1807" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/43047" source="BID" patch="1">43047</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=627703" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=627703</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://www.computerworld.com/s/article/9195058/Researcher_to_release_Web_based_Android_attack" source="MISC">http://www.computerworld.com/s/article/9195058/Researcher_to_release_Web_based_Android_attack</ref>
      <ref url="http://trac.webkit.org/changeset/64706" source="CONFIRM">http://trac.webkit.org/changeset/64706</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4333" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4333</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11964" source="OVAL">oval:org.mitre.oval:def:11964</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-09-07-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1808" published="2010-08-25" name="CVE-2010-1808" modified="2010-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://securitytracker.com/id?1024359" source="SECTRACK">1024359</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE" adv="1">APPLE-SA-2010-08-24-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="apple_type_services">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1809" published="2010-09-09" name="CVE-2010-1809" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61694" source="XF">appleios-voiceover-weak-security(61694)</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0" />
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.1.1" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1810" published="2010-09-09" name="CVE-2010-1810" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61695" source="XF">appleios-facetime-sec-bypass(61695)</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0" />
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.1.1" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1811" published="2010-09-09" name="CVE-2010-1811" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61696" source="XF">appleios-tiff-code-exec(61696)</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1812" published="2010-09-09" name="CVE-2010-1812" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61699" source="XF">appleios-selections-code-exec(61699)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/43079" source="BID">43079</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4455" source="CONFIRM">http://support.apple.com/kb/HT4455</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html" source="APPLE">APPLE-SA-2010-11-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1813" published="2010-09-09" name="CVE-2010-1813" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61700" source="XF">appleios-html-object-code-exec(61700)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4455" source="CONFIRM">http://support.apple.com/kb/HT4455</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html" source="APPLE">APPLE-SA-2010-11-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1814" published="2010-09-09" name="CVE-2010-1814" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61701" source="XF">appleios-formmenus-code-exec(61701)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/43083" source="BID">43083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4455" source="CONFIRM">http://support.apple.com/kb/HT4455</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html" source="APPLE">APPLE-SA-2010-11-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1815" published="2010-09-09" name="CVE-2010-1815" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61702" source="XF">appleios-scrollbars-code-exec(61702)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0552" source="VUPEN">ADV-2011-0552</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0216" source="VUPEN">ADV-2011-0216</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/2722" source="VUPEN">ADV-2010-2722</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1006-1" source="UBUNTU">USN-1006-1</ref>
      <ref url="http://www.securityfocus.com/bid/43081" source="BID">43081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0177.html" source="REDHAT">RHSA-2011:0177</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:039" source="MANDRIVA">MDVSA-2011:039</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4455" source="CONFIRM">http://support.apple.com/kb/HT4455</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://secunia.com/advisories/43086" source="SECUNIA">43086</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/41856" source="SECUNIA">41856</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html" source="APPLE">APPLE-SA-2010-11-18-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1817" published="2010-09-09" name="CVE-2010-1817" modified="2010-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61697" source="XF">appleios-gif-bo(61697)</ref>
      <ref url="http://support.apple.com/kb/HT4334" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4334</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html" source="APPLE" adv="1">APPLE-SA-2010-09-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num="" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:iphone" />
        <vers num="3.0" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:ipodtouch" />
        <vers num="3.0.1" edition="-:iphone" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:iphone" />
        <vers num="3.1" edition="-:ipodtouch" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:iphone" />
        <vers num="3.1.2" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-" />
        <vers num="3.1.3" edition="-:ipodtouch" />
        <vers num="3.1.3" edition="-:iphone" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:ipodtouch" />
        <vers num="3.2" edition="-:iphone" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:ipodtouch" />
        <vers num="4.0" edition="-:iphone" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:iphone" />
        <vers num="4.0.1" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-" />
        <vers prev="1" num="4.0.2" edition="-:ipodtouch" />
        <vers prev="1" num="4.0.2" edition="-:iphone" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1818" published="2010-08-31" name="CVE-2010-1818" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshaling of an untrusted pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/browser/apple_quicktime_marshaled_punk.rb" source="MISC">https://www.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/browser/apple_quicktime_marshaled_punk.rb</ref>
      <ref url="http://threatpost.com/en_us/blogs/new-remote-flaw-apple-quicktime-bypasses-aslr-and-dep-083010" source="MISC">http://threatpost.com/en_us/blogs/new-remote-flaw-apple-quicktime-bypasses-aslr-and-dep-083010</ref>
      <ref url="http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=69&amp;Itemid=1" source="MISC">http://reversemode.com/index.php?option=com_content&amp;task=view&amp;id=69&amp;Itemid=1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7523" source="OVAL">oval:org.mitre.oval:def:7523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="6.0" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.2.0" />
        <vers num="6.3.0" />
        <vers num="6.4.0" />
        <vers num="6.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.1" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.2.0" />
        <vers num="7.2.1" />
        <vers num="7.3" />
        <vers num="7.3.0" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" />
        <vers num="7.4.1" />
        <vers num="7.4.5" />
        <vers num="7.5.0" />
        <vers num="7.5.5" />
        <vers num="7.6.0" />
        <vers num="7.6.1" />
        <vers num="7.6.2" />
        <vers num="7.6.5" />
        <vers num="7.6.6" />
        <vers num="7.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1820" published="2010-09-21" name="CVE-2010-1820" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Sep/msg00004.html" source="APPLE" patch="1" adv="1">APPLE-SA-2010-09-20-1</ref>
      <ref url="http://www.securityfocus.com/bid/43341" source="BID">43341</ref>
      <ref url="http://support.apple.com/kb/HT4361" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4361</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12109" source="OVAL">oval:org.mitre.oval:def:12109</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1822" published="2010-10-04" name="CVE-2010-1822" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=45562" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=45562</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN" adv="1">ADV-2010-3046</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://support.apple.com/kb/HT4455" source="CONFIRM">http://support.apple.com/kb/HT4455</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA" adv="1">42314</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6691" source="OVAL">oval:org.mitre.oval:def:6691</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html" source="APPLE">APPLE-SA-2010-11-18-1</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=55114" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=55114</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.0b" />
        <vers num="3.0.1" />
        <vers num="3.0.1b" />
        <vers num="3.0.2" />
        <vers num="3.0.2b" />
        <vers num="3.0.3" />
        <vers num="3.0.3b" />
        <vers num="3.0.4" />
        <vers num="3.0.4b" />
        <vers num="3.1.0" />
        <vers num="3.1.0b" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" />
        <vers num="5.0.342.8" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.369.1" />
        <vers num="5.0.369.2" />
        <vers num="5.0.370.0" />
        <vers num="5.0.371.0" />
        <vers num="5.0.372.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.125" />
        <vers num="5.0.375.126" />
        <vers num="5.0.375.127" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.70" />
        <vers num="5.0.375.71" />
        <vers num="5.0.375.72" />
        <vers num="5.0.375.73" />
        <vers num="5.0.375.74" />
        <vers num="5.0.375.75" />
        <vers num="5.0.375.76" />
        <vers num="5.0.375.77" />
        <vers num="5.0.375.78" />
        <vers num="5.0.375.79" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.80" />
        <vers num="5.0.375.81" />
        <vers num="5.0.375.82" />
        <vers num="5.0.375.83" />
        <vers num="5.0.375.84" />
        <vers num="5.0.375.85" />
        <vers num="5.0.375.86" />
        <vers num="5.0.375.87" />
        <vers num="5.0.375.88" />
        <vers num="5.0.375.89" />
        <vers num="5.0.375.9" />
        <vers num="5.0.375.90" />
        <vers num="5.0.375.91" />
        <vers num="5.0.375.92" />
        <vers num="5.0.375.93" />
        <vers num="5.0.375.94" />
        <vers num="5.0.375.95" />
        <vers num="5.0.375.96" />
        <vers num="5.0.375.97" />
        <vers num="5.0.375.98" />
        <vers num="5.0.375.99" />
        <vers num="5.0.376.0" />
        <vers num="5.0.378.0" />
        <vers num="5.0.379.0" />
        <vers num="5.0.380.0" />
        <vers num="5.0.381.0" />
        <vers num="5.0.382.0" />
        <vers num="5.0.382.3" />
        <vers num="5.0.383.0" />
        <vers num="5.0.384.0" />
        <vers num="5.0.385.0" />
        <vers num="5.0.386.0" />
        <vers num="5.0.387.0" />
        <vers num="5.0.390.0" />
        <vers num="5.0.391.0" />
        <vers num="5.0.392.0" />
        <vers num="5.0.393.0" />
        <vers num="5.0.394.0" />
        <vers num="5.0.395.0" />
        <vers num="5.0.396.0" />
        <vers num="6.0.397.0" />
        <vers num="6.0.398.0" />
        <vers num="6.0.399.0" />
        <vers num="6.0.400.0" />
        <vers num="6.0.401.0" />
        <vers num="6.0.401.1" />
        <vers num="6.0.403.0" />
        <vers num="6.0.404.0" />
        <vers num="6.0.404.1" />
        <vers num="6.0.404.2" />
        <vers num="6.0.405.0" />
        <vers num="6.0.406.0" />
        <vers num="6.0.407.0" />
        <vers num="6.0.408.0" />
        <vers num="6.0.408.1" />
        <vers num="6.0.408.10" />
        <vers num="6.0.408.2" />
        <vers num="6.0.408.3" />
        <vers num="6.0.408.4" />
        <vers num="6.0.408.5" />
        <vers num="6.0.408.6" />
        <vers num="6.0.408.7" />
        <vers num="6.0.408.8" />
        <vers num="6.0.408.9" />
        <vers num="6.0.409.0" />
        <vers num="6.0.410.0" />
        <vers num="6.0.411.0" />
        <vers num="6.0.412.0" />
        <vers num="6.0.413.0" />
        <vers num="6.0.414.0" />
        <vers num="6.0.415.0" />
        <vers num="6.0.415.1" />
        <vers num="6.0.416.0" />
        <vers num="6.0.416.1" />
        <vers num="6.0.417.0" />
        <vers num="6.0.418.0" />
        <vers num="6.0.418.1" />
        <vers num="6.0.418.2" />
        <vers num="6.0.418.3" />
        <vers num="6.0.418.4" />
        <vers num="6.0.418.5" />
        <vers num="6.0.418.6" />
        <vers num="6.0.418.7" />
        <vers num="6.0.418.8" />
        <vers num="6.0.418.9" />
        <vers num="6.0.419.0" />
        <vers num="6.0.421.0" />
        <vers num="6.0.422.0" />
        <vers num="6.0.423.0" />
        <vers num="6.0.424.0" />
        <vers num="6.0.425.0" />
        <vers num="6.0.426.0" />
        <vers num="6.0.427.0" />
        <vers num="6.0.428.0" />
        <vers num="6.0.430.0" />
        <vers num="6.0.431.0" />
        <vers num="6.0.432.0" />
        <vers num="6.0.433.0" />
        <vers num="6.0.434.0" />
        <vers num="6.0.435.0" />
        <vers num="6.0.436.0" />
        <vers num="6.0.437.0" />
        <vers num="6.0.437.1" />
        <vers num="6.0.437.2" />
        <vers num="6.0.437.3" />
        <vers num="6.0.438.0" />
        <vers num="6.0.440.0" />
        <vers num="6.0.441.0" />
        <vers num="6.0.443.0" />
        <vers num="6.0.444.0" />
        <vers num="6.0.445.0" />
        <vers num="6.0.445.1" />
        <vers num="6.0.446.0" />
        <vers num="6.0.447.0" />
        <vers num="6.0.447.1" />
        <vers num="6.0.447.2" />
        <vers num="6.0.449.0" />
        <vers num="6.0.450.0" />
        <vers num="6.0.450.1" />
        <vers num="6.0.450.2" />
        <vers num="6.0.450.3" />
        <vers num="6.0.450.4" />
        <vers num="6.0.451.0" />
        <vers num="6.0.452.0" />
        <vers num="6.0.452.1" />
        <vers num="6.0.453.0" />
        <vers num="6.0.453.1" />
        <vers num="6.0.454.0" />
        <vers num="6.0.455.0" />
        <vers num="6.0.456.0" />
        <vers num="6.0.457.0" />
        <vers num="6.0.458.0" />
        <vers num="6.0.458.1" />
        <vers num="6.0.458.2" />
        <vers num="6.0.459.0" />
        <vers num="6.0.460.0" />
        <vers num="6.0.461.0" />
        <vers num="6.0.462.0" />
        <vers num="6.0.464.1" />
        <vers num="6.0.465.1" />
        <vers num="6.0.472.58" />
        <vers num="6.0.472.59" />
        <vers num="6.0.472.60" />
        <vers prev="1" num="6.0.472.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1823" published="2010-09-24" name="CVE-2010-1823" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=44533" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=44533</ref>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=43055" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=43055</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7405" source="OVAL">oval:org.mitre.oval:def:7405</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=50250" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=50250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" />
        <vers num="5.0.342.8" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.369.1" />
        <vers num="5.0.369.2" />
        <vers num="5.0.370.0" />
        <vers num="5.0.371.0" />
        <vers num="5.0.372.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.125" />
        <vers num="5.0.375.126" />
        <vers num="5.0.375.127" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.70" />
        <vers num="5.0.375.71" />
        <vers num="5.0.375.72" />
        <vers num="5.0.375.73" />
        <vers num="5.0.375.74" />
        <vers num="5.0.375.75" />
        <vers num="5.0.375.76" />
        <vers num="5.0.375.77" />
        <vers num="5.0.375.78" />
        <vers num="5.0.375.79" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.80" />
        <vers num="5.0.375.81" />
        <vers num="5.0.375.82" />
        <vers num="5.0.375.83" />
        <vers num="5.0.375.84" />
        <vers num="5.0.375.85" />
        <vers num="5.0.375.86" />
        <vers num="5.0.375.87" />
        <vers num="5.0.375.88" />
        <vers num="5.0.375.89" />
        <vers num="5.0.375.9" />
        <vers num="5.0.375.90" />
        <vers num="5.0.375.91" />
        <vers num="5.0.375.92" />
        <vers num="5.0.375.93" />
        <vers num="5.0.375.94" />
        <vers num="5.0.375.95" />
        <vers num="5.0.375.96" />
        <vers num="5.0.375.97" />
        <vers num="5.0.375.98" />
        <vers num="5.0.375.99" />
        <vers num="6.0.399.0" />
        <vers num="6.0.400.0" />
        <vers num="6.0.401.0" />
        <vers num="6.0.401.1" />
        <vers num="6.0.403.0" />
        <vers num="6.0.404.0" />
        <vers num="6.0.404.1" />
        <vers num="6.0.404.2" />
        <vers num="6.0.405.0" />
        <vers num="6.0.406.0" />
        <vers num="6.0.407.0" />
        <vers num="6.0.408.0" />
        <vers num="6.0.408.1" />
        <vers num="6.0.408.10" />
        <vers num="6.0.408.2" />
        <vers num="6.0.408.3" />
        <vers num="6.0.408.4" />
        <vers num="6.0.408.5" />
        <vers num="6.0.408.6" />
        <vers num="6.0.408.7" />
        <vers num="6.0.408.8" />
        <vers num="6.0.408.9" />
        <vers num="6.0.409.0" />
        <vers num="6.0.410.0" />
        <vers num="6.0.411.0" />
        <vers num="6.0.412.0" />
        <vers num="6.0.413.0" />
        <vers num="6.0.414.0" />
        <vers num="6.0.415.0" />
        <vers num="6.0.415.1" />
        <vers num="6.0.416.0" />
        <vers num="6.0.416.1" />
        <vers num="6.0.417.0" />
        <vers num="6.0.418.0" />
        <vers num="6.0.418.1" />
        <vers num="6.0.418.2" />
        <vers num="6.0.418.3" />
        <vers num="6.0.418.4" />
        <vers num="6.0.418.5" />
        <vers num="6.0.418.6" />
        <vers num="6.0.418.7" />
        <vers num="6.0.418.8" />
        <vers num="6.0.418.9" />
        <vers num="6.0.419.0" />
        <vers num="6.0.421.0" />
        <vers num="6.0.422.0" />
        <vers num="6.0.423.0" />
        <vers num="6.0.424.0" />
        <vers num="6.0.425.0" />
        <vers num="6.0.426.0" />
        <vers num="6.0.427.0" />
        <vers num="6.0.428.0" />
        <vers num="6.0.430.0" />
        <vers num="6.0.431.0" />
        <vers num="6.0.432.0" />
        <vers num="6.0.433.0" />
        <vers num="6.0.434.0" />
        <vers num="6.0.435.0" />
        <vers num="6.0.436.0" />
        <vers num="6.0.437.0" />
        <vers num="6.0.437.1" />
        <vers num="6.0.437.2" />
        <vers num="6.0.437.3" />
        <vers num="6.0.438.0" />
        <vers num="6.0.440.0" />
        <vers num="6.0.441.0" />
        <vers num="6.0.443.0" />
        <vers num="6.0.444.0" />
        <vers num="6.0.445.0" />
        <vers num="6.0.445.1" />
        <vers num="6.0.446.0" />
        <vers num="6.0.447.0" />
        <vers num="6.0.447.1" />
        <vers num="6.0.447.2" />
        <vers num="6.0.449.0" />
        <vers num="6.0.450.0" />
        <vers num="6.0.450.1" />
        <vers num="6.0.450.2" />
        <vers num="6.0.450.3" />
        <vers num="6.0.450.4" />
        <vers num="6.0.451.0" />
        <vers num="6.0.452.0" />
        <vers num="6.0.452.1" />
        <vers num="6.0.453.0" />
        <vers num="6.0.453.1" />
        <vers num="6.0.454.0" />
        <vers num="6.0.455.0" />
        <vers num="6.0.456.0" />
        <vers num="6.0.457.0" />
        <vers num="6.0.458.0" />
        <vers num="6.0.458.1" />
        <vers num="6.0.458.2" />
        <vers num="6.0.459.0" />
        <vers num="6.0.460.0" />
        <vers num="6.0.461.0" />
        <vers num="6.0.462.0" />
        <vers num="6.0.464.1" />
        <vers num="6.0.465.1" />
        <vers num="6.0.465.2" />
        <vers num="6.0.466.0" />
        <vers num="6.0.466.1" />
        <vers num="6.0.466.2" />
        <vers num="6.0.466.3" />
        <vers num="6.0.466.4" />
        <vers num="6.0.466.5" />
        <vers num="6.0.466.6" />
        <vers num="6.0.467.0" />
        <vers num="6.0.469.0" />
        <vers num="6.0.470.0" />
        <vers num="6.0.471.0" />
        <vers num="6.0.472.0" />
        <vers num="6.0.472.1" />
        <vers num="6.0.472.10" />
        <vers num="6.0.472.11" />
        <vers num="6.0.472.12" />
        <vers num="6.0.472.13" />
        <vers num="6.0.472.14" />
        <vers num="6.0.472.15" />
        <vers num="6.0.472.16" />
        <vers num="6.0.472.17" />
        <vers num="6.0.472.18" />
        <vers num="6.0.472.19" />
        <vers num="6.0.472.2" />
        <vers num="6.0.472.20" />
        <vers num="6.0.472.21" />
        <vers num="6.0.472.22" />
        <vers num="6.0.472.23" />
        <vers num="6.0.472.24" />
        <vers num="6.0.472.25" />
        <vers num="6.0.472.26" />
        <vers num="6.0.472.27" />
        <vers num="6.0.472.28" />
        <vers num="6.0.472.29" />
        <vers num="6.0.472.3" />
        <vers num="6.0.472.30" />
        <vers num="6.0.472.31" />
        <vers num="6.0.472.32" />
        <vers num="6.0.472.33" />
        <vers num="6.0.472.34" />
        <vers num="6.0.472.35" />
        <vers num="6.0.472.36" />
        <vers num="6.0.472.37" />
        <vers num="6.0.472.38" />
        <vers num="6.0.472.39" />
        <vers num="6.0.472.4" />
        <vers num="6.0.472.40" />
        <vers num="6.0.472.41" />
        <vers num="6.0.472.42" />
        <vers num="6.0.472.43" />
        <vers num="6.0.472.44" />
        <vers num="6.0.472.45" />
        <vers num="6.0.472.46" />
        <vers num="6.0.472.47" />
        <vers num="6.0.472.48" />
        <vers num="6.0.472.49" />
        <vers num="6.0.472.5" />
        <vers num="6.0.472.50" />
        <vers num="6.0.472.51" />
        <vers num="6.0.472.52" />
        <vers num="6.0.472.53" />
        <vers num="6.0.472.54" />
        <vers num="6.0.472.55" />
        <vers num="6.0.472.56" />
        <vers num="6.0.472.57" />
        <vers prev="1" num="6.0.472.58" />
        <vers num="6.0.472.6" />
        <vers num="6.0.472.7" />
        <vers num="6.0.472.8" />
        <vers num="6.0.472.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1824" published="2010-09-24" name="CVE-2010-1824" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=43260" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=43260</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-095" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-095</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7151" source="OVAL">oval:org.mitre.oval:def:7151</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=50712" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=50712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" />
        <vers num="5.0.342.8" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.369.1" />
        <vers num="5.0.369.2" />
        <vers num="5.0.370.0" />
        <vers num="5.0.371.0" />
        <vers num="5.0.372.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.125" />
        <vers num="5.0.375.126" />
        <vers num="5.0.375.127" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.70" />
        <vers num="5.0.375.71" />
        <vers num="5.0.375.72" />
        <vers num="5.0.375.73" />
        <vers num="5.0.375.74" />
        <vers num="5.0.375.75" />
        <vers num="5.0.375.76" />
        <vers num="5.0.375.77" />
        <vers num="5.0.375.78" />
        <vers num="5.0.375.79" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.80" />
        <vers num="5.0.375.81" />
        <vers num="5.0.375.82" />
        <vers num="5.0.375.83" />
        <vers num="5.0.375.84" />
        <vers num="5.0.375.85" />
        <vers num="5.0.375.86" />
        <vers num="5.0.375.87" />
        <vers num="5.0.375.88" />
        <vers num="5.0.375.89" />
        <vers num="5.0.375.9" />
        <vers num="5.0.375.90" />
        <vers num="5.0.375.91" />
        <vers num="5.0.375.92" />
        <vers num="5.0.375.93" />
        <vers num="5.0.375.94" />
        <vers num="5.0.375.95" />
        <vers num="5.0.375.96" />
        <vers num="5.0.375.97" />
        <vers num="5.0.375.98" />
        <vers num="5.0.375.99" />
        <vers num="6.0.399.0" />
        <vers num="6.0.400.0" />
        <vers num="6.0.401.0" />
        <vers num="6.0.401.1" />
        <vers num="6.0.403.0" />
        <vers num="6.0.404.0" />
        <vers num="6.0.404.1" />
        <vers num="6.0.404.2" />
        <vers num="6.0.405.0" />
        <vers num="6.0.406.0" />
        <vers num="6.0.407.0" />
        <vers num="6.0.408.0" />
        <vers num="6.0.408.1" />
        <vers num="6.0.408.10" />
        <vers num="6.0.408.2" />
        <vers num="6.0.408.3" />
        <vers num="6.0.408.4" />
        <vers num="6.0.408.5" />
        <vers num="6.0.408.6" />
        <vers num="6.0.408.7" />
        <vers num="6.0.408.8" />
        <vers num="6.0.408.9" />
        <vers num="6.0.409.0" />
        <vers num="6.0.410.0" />
        <vers num="6.0.411.0" />
        <vers num="6.0.412.0" />
        <vers num="6.0.413.0" />
        <vers num="6.0.414.0" />
        <vers num="6.0.415.0" />
        <vers num="6.0.415.1" />
        <vers num="6.0.416.0" />
        <vers num="6.0.416.1" />
        <vers num="6.0.417.0" />
        <vers num="6.0.418.0" />
        <vers num="6.0.418.1" />
        <vers num="6.0.418.2" />
        <vers num="6.0.418.3" />
        <vers num="6.0.418.4" />
        <vers num="6.0.418.5" />
        <vers num="6.0.418.6" />
        <vers num="6.0.418.7" />
        <vers num="6.0.418.8" />
        <vers num="6.0.418.9" />
        <vers num="6.0.419.0" />
        <vers num="6.0.421.0" />
        <vers num="6.0.422.0" />
        <vers num="6.0.423.0" />
        <vers num="6.0.424.0" />
        <vers num="6.0.425.0" />
        <vers num="6.0.426.0" />
        <vers num="6.0.427.0" />
        <vers num="6.0.428.0" />
        <vers num="6.0.430.0" />
        <vers num="6.0.431.0" />
        <vers num="6.0.432.0" />
        <vers num="6.0.433.0" />
        <vers num="6.0.434.0" />
        <vers num="6.0.435.0" />
        <vers num="6.0.436.0" />
        <vers num="6.0.437.0" />
        <vers num="6.0.437.1" />
        <vers num="6.0.437.2" />
        <vers num="6.0.437.3" />
        <vers num="6.0.438.0" />
        <vers num="6.0.440.0" />
        <vers num="6.0.441.0" />
        <vers num="6.0.443.0" />
        <vers num="6.0.444.0" />
        <vers num="6.0.445.0" />
        <vers num="6.0.445.1" />
        <vers num="6.0.446.0" />
        <vers num="6.0.447.0" />
        <vers num="6.0.447.1" />
        <vers num="6.0.447.2" />
        <vers num="6.0.449.0" />
        <vers num="6.0.450.0" />
        <vers num="6.0.450.1" />
        <vers num="6.0.450.2" />
        <vers num="6.0.450.3" />
        <vers num="6.0.450.4" />
        <vers num="6.0.451.0" />
        <vers num="6.0.452.0" />
        <vers num="6.0.452.1" />
        <vers num="6.0.453.0" />
        <vers num="6.0.453.1" />
        <vers num="6.0.454.0" />
        <vers num="6.0.455.0" />
        <vers num="6.0.456.0" />
        <vers num="6.0.457.0" />
        <vers num="6.0.458.0" />
        <vers num="6.0.458.1" />
        <vers num="6.0.458.2" />
        <vers num="6.0.459.0" />
        <vers num="6.0.460.0" />
        <vers num="6.0.461.0" />
        <vers num="6.0.462.0" />
        <vers num="6.0.464.1" />
        <vers num="6.0.465.1" />
        <vers num="6.0.465.2" />
        <vers num="6.0.466.0" />
        <vers num="6.0.466.1" />
        <vers num="6.0.466.2" />
        <vers num="6.0.466.3" />
        <vers num="6.0.466.4" />
        <vers num="6.0.466.5" />
        <vers num="6.0.466.6" />
        <vers num="6.0.467.0" />
        <vers num="6.0.469.0" />
        <vers num="6.0.470.0" />
        <vers num="6.0.471.0" />
        <vers num="6.0.472.0" />
        <vers num="6.0.472.1" />
        <vers num="6.0.472.10" />
        <vers num="6.0.472.11" />
        <vers num="6.0.472.12" />
        <vers num="6.0.472.13" />
        <vers num="6.0.472.14" />
        <vers num="6.0.472.15" />
        <vers num="6.0.472.16" />
        <vers num="6.0.472.17" />
        <vers num="6.0.472.18" />
        <vers num="6.0.472.19" />
        <vers num="6.0.472.2" />
        <vers num="6.0.472.20" />
        <vers num="6.0.472.21" />
        <vers num="6.0.472.22" />
        <vers num="6.0.472.23" />
        <vers num="6.0.472.24" />
        <vers num="6.0.472.25" />
        <vers num="6.0.472.26" />
        <vers num="6.0.472.27" />
        <vers num="6.0.472.28" />
        <vers num="6.0.472.29" />
        <vers num="6.0.472.3" />
        <vers num="6.0.472.30" />
        <vers num="6.0.472.31" />
        <vers num="6.0.472.32" />
        <vers num="6.0.472.33" />
        <vers num="6.0.472.34" />
        <vers num="6.0.472.35" />
        <vers num="6.0.472.36" />
        <vers num="6.0.472.37" />
        <vers num="6.0.472.38" />
        <vers num="6.0.472.39" />
        <vers num="6.0.472.4" />
        <vers num="6.0.472.40" />
        <vers num="6.0.472.41" />
        <vers num="6.0.472.42" />
        <vers num="6.0.472.43" />
        <vers num="6.0.472.44" />
        <vers num="6.0.472.45" />
        <vers num="6.0.472.46" />
        <vers num="6.0.472.47" />
        <vers num="6.0.472.48" />
        <vers num="6.0.472.49" />
        <vers num="6.0.472.5" />
        <vers num="6.0.472.50" />
        <vers num="6.0.472.51" />
        <vers num="6.0.472.52" />
        <vers num="6.0.472.53" />
        <vers num="6.0.472.54" />
        <vers num="6.0.472.55" />
        <vers num="6.0.472.56" />
        <vers num="6.0.472.57" />
        <vers prev="1" num="6.0.472.58" />
        <vers num="6.0.472.6" />
        <vers num="6.0.472.7" />
        <vers num="6.0.472.8" />
        <vers num="6.0.472.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1825" published="2010-09-24" name="CVE-2010-1825" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=43587" source="CONFIRM">https://bugs.webkit.org/show_bug.cgi?id=43587</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7202" source="OVAL">oval:org.mitre.oval:def:7202</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=51252" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=51252</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="0.2.149.27" />
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.48" />
        <vers num="1.0.154.52" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.31" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.193.2" edition="beta" />
        <vers num="3.0.195.2" />
        <vers num="3.0.195.21" />
        <vers num="3.0.195.24" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.32" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" />
        <vers num="5.0.342.8" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.369.1" />
        <vers num="5.0.369.2" />
        <vers num="5.0.370.0" />
        <vers num="5.0.371.0" />
        <vers num="5.0.372.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.125" />
        <vers num="5.0.375.126" />
        <vers num="5.0.375.127" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers num="5.0.375.54" />
        <vers num="5.0.375.55" />
        <vers num="5.0.375.56" />
        <vers num="5.0.375.57" />
        <vers num="5.0.375.58" />
        <vers num="5.0.375.59" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.60" />
        <vers num="5.0.375.61" />
        <vers num="5.0.375.62" />
        <vers num="5.0.375.63" />
        <vers num="5.0.375.64" />
        <vers num="5.0.375.65" />
        <vers num="5.0.375.66" />
        <vers num="5.0.375.67" />
        <vers num="5.0.375.68" />
        <vers num="5.0.375.69" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.70" />
        <vers num="5.0.375.71" />
        <vers num="5.0.375.72" />
        <vers num="5.0.375.73" />
        <vers num="5.0.375.74" />
        <vers num="5.0.375.75" />
        <vers num="5.0.375.76" />
        <vers num="5.0.375.77" />
        <vers num="5.0.375.78" />
        <vers num="5.0.375.79" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.80" />
        <vers num="5.0.375.81" />
        <vers num="5.0.375.82" />
        <vers num="5.0.375.83" />
        <vers num="5.0.375.84" />
        <vers num="5.0.375.85" />
        <vers num="5.0.375.86" />
        <vers num="5.0.375.87" />
        <vers num="5.0.375.88" />
        <vers num="5.0.375.89" />
        <vers num="5.0.375.9" />
        <vers num="5.0.375.90" />
        <vers num="5.0.375.91" />
        <vers num="5.0.375.92" />
        <vers num="5.0.375.93" />
        <vers num="5.0.375.94" />
        <vers num="5.0.375.95" />
        <vers num="5.0.375.96" />
        <vers num="5.0.375.97" />
        <vers num="5.0.375.98" />
        <vers num="5.0.375.99" />
        <vers num="6.0.399.0" />
        <vers num="6.0.400.0" />
        <vers num="6.0.401.0" />
        <vers num="6.0.401.1" />
        <vers num="6.0.403.0" />
        <vers num="6.0.404.0" />
        <vers num="6.0.404.1" />
        <vers num="6.0.404.2" />
        <vers num="6.0.405.0" />
        <vers num="6.0.406.0" />
        <vers num="6.0.407.0" />
        <vers num="6.0.408.0" />
        <vers num="6.0.408.1" />
        <vers num="6.0.408.10" />
        <vers num="6.0.408.2" />
        <vers num="6.0.408.3" />
        <vers num="6.0.408.4" />
        <vers num="6.0.408.5" />
        <vers num="6.0.408.6" />
        <vers num="6.0.408.7" />
        <vers num="6.0.408.8" />
        <vers num="6.0.408.9" />
        <vers num="6.0.409.0" />
        <vers num="6.0.410.0" />
        <vers num="6.0.411.0" />
        <vers num="6.0.412.0" />
        <vers num="6.0.413.0" />
        <vers num="6.0.414.0" />
        <vers num="6.0.415.0" />
        <vers num="6.0.415.1" />
        <vers num="6.0.416.0" />
        <vers num="6.0.416.1" />
        <vers num="6.0.417.0" />
        <vers num="6.0.418.0" />
        <vers num="6.0.418.1" />
        <vers num="6.0.418.2" />
        <vers num="6.0.418.3" />
        <vers num="6.0.418.4" />
        <vers num="6.0.418.5" />
        <vers num="6.0.418.6" />
        <vers num="6.0.418.7" />
        <vers num="6.0.418.8" />
        <vers num="6.0.418.9" />
        <vers num="6.0.419.0" />
        <vers num="6.0.421.0" />
        <vers num="6.0.422.0" />
        <vers num="6.0.423.0" />
        <vers num="6.0.424.0" />
        <vers num="6.0.425.0" />
        <vers num="6.0.426.0" />
        <vers num="6.0.427.0" />
        <vers num="6.0.428.0" />
        <vers num="6.0.430.0" />
        <vers num="6.0.431.0" />
        <vers num="6.0.432.0" />
        <vers num="6.0.433.0" />
        <vers num="6.0.434.0" />
        <vers num="6.0.435.0" />
        <vers num="6.0.436.0" />
        <vers num="6.0.437.0" />
        <vers num="6.0.437.1" />
        <vers num="6.0.437.2" />
        <vers num="6.0.437.3" />
        <vers num="6.0.438.0" />
        <vers num="6.0.440.0" />
        <vers num="6.0.441.0" />
        <vers num="6.0.443.0" />
        <vers num="6.0.444.0" />
        <vers num="6.0.445.0" />
        <vers num="6.0.445.1" />
        <vers num="6.0.446.0" />
        <vers num="6.0.447.0" />
        <vers num="6.0.447.1" />
        <vers num="6.0.447.2" />
        <vers num="6.0.449.0" />
        <vers num="6.0.450.0" />
        <vers num="6.0.450.1" />
        <vers num="6.0.450.2" />
        <vers num="6.0.450.3" />
        <vers num="6.0.450.4" />
        <vers num="6.0.451.0" />
        <vers num="6.0.452.0" />
        <vers num="6.0.452.1" />
        <vers num="6.0.453.0" />
        <vers num="6.0.453.1" />
        <vers num="6.0.454.0" />
        <vers num="6.0.455.0" />
        <vers num="6.0.456.0" />
        <vers num="6.0.457.0" />
        <vers num="6.0.458.0" />
        <vers num="6.0.458.1" />
        <vers num="6.0.458.2" />
        <vers num="6.0.459.0" />
        <vers num="6.0.460.0" />
        <vers num="6.0.461.0" />
        <vers num="6.0.462.0" />
        <vers num="6.0.464.1" />
        <vers num="6.0.465.1" />
        <vers num="6.0.465.2" />
        <vers num="6.0.466.0" />
        <vers num="6.0.466.1" />
        <vers num="6.0.466.2" />
        <vers num="6.0.466.3" />
        <vers num="6.0.466.4" />
        <vers num="6.0.466.5" />
        <vers num="6.0.466.6" />
        <vers num="6.0.467.0" />
        <vers num="6.0.469.0" />
        <vers num="6.0.470.0" />
        <vers num="6.0.471.0" />
        <vers num="6.0.472.0" />
        <vers num="6.0.472.1" />
        <vers num="6.0.472.10" />
        <vers num="6.0.472.11" />
        <vers num="6.0.472.12" />
        <vers num="6.0.472.13" />
        <vers num="6.0.472.14" />
        <vers num="6.0.472.15" />
        <vers num="6.0.472.16" />
        <vers num="6.0.472.17" />
        <vers num="6.0.472.18" />
        <vers num="6.0.472.19" />
        <vers num="6.0.472.2" />
        <vers num="6.0.472.20" />
        <vers num="6.0.472.21" />
        <vers num="6.0.472.22" />
        <vers num="6.0.472.23" />
        <vers num="6.0.472.24" />
        <vers num="6.0.472.25" />
        <vers num="6.0.472.26" />
        <vers num="6.0.472.27" />
        <vers num="6.0.472.28" />
        <vers num="6.0.472.29" />
        <vers num="6.0.472.3" />
        <vers num="6.0.472.30" />
        <vers num="6.0.472.31" />
        <vers num="6.0.472.32" />
        <vers num="6.0.472.33" />
        <vers num="6.0.472.34" />
        <vers num="6.0.472.35" />
        <vers num="6.0.472.36" />
        <vers num="6.0.472.37" />
        <vers num="6.0.472.38" />
        <vers num="6.0.472.39" />
        <vers num="6.0.472.4" />
        <vers num="6.0.472.40" />
        <vers num="6.0.472.41" />
        <vers num="6.0.472.42" />
        <vers num="6.0.472.43" />
        <vers num="6.0.472.44" />
        <vers num="6.0.472.45" />
        <vers num="6.0.472.46" />
        <vers num="6.0.472.47" />
        <vers num="6.0.472.48" />
        <vers num="6.0.472.49" />
        <vers num="6.0.472.5" />
        <vers num="6.0.472.50" />
        <vers num="6.0.472.51" />
        <vers num="6.0.472.52" />
        <vers num="6.0.472.53" />
        <vers num="6.0.472.54" />
        <vers num="6.0.472.55" />
        <vers num="6.0.472.56" />
        <vers num="6.0.472.57" />
        <vers prev="1" num="6.0.472.58" />
        <vers num="6.0.472.6" />
        <vers num="6.0.472.7" />
        <vers num="6.0.472.8" />
        <vers num="6.0.472.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1828" published="2010-11-15" name="CVE-2010-1828" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1829" published="2010-11-15" name="CVE-2010-1829" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1830" published="2010-11-15" name="CVE-2010-1830" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1831" published="2010-11-15" name="CVE-2010-1831" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a long name of an embedded font in a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1832" published="2010-11-15" name="CVE-2010-1832" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code via a crafted embedded font in a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1833" published="2010-11-15" name="CVE-2010-1833" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1834" published="2010-11-15" name="CVE-2010-1834" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1836" published="2010-11-15" name="CVE-2010-1836" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1837" published="2010-11-15" name="CVE-2010-1837" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/44808" source="BID">44808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1838" published="2010-11-15" name="CVE-2010-1838" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/44817" source="BID">44817</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1840" published="2010-11-15" name="CVE-2010-1840" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1841" published="2010-11-15" name="CVE-2010-1841" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/44815" source="BID">44815</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1842" published="2010-11-15" name="CVE-2010-1842" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/44803" source="BID">44803</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1843" published="2010-11-16" name="CVE-2010-1843" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted PIM packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1844" published="2010-11-16" name="CVE-2010-1844" modified="2011-01-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/bid/44813" source="BID">44813</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1845" published="2010-11-16" name="CVE-2010-1845" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514867/100/0/threaded" source="BUGTRAQ">20101122 NGS00015 Patch Notification: ImageIO Memory Corruption</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1846" published="2010-11-16" name="CVE-2010-1846" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8" />
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1847" published="2010-11-16" name="CVE-2010-1847" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://www.securitytracker.com/id?1024723" source="SECTRACK">1024723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE" adv="1">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0" />
        <vers num="10.6.1" />
        <vers num="10.6.2" />
        <vers num="10.6.3" />
        <vers num="10.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1848" published="2010-06-07" name="CVE-2010-1848" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0824.html" source="REDHAT">RHSA-2010:0824</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0442.html" source="REDHAT">RHSA-2010:0442</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:107" source="MANDRIVA">MDVSA-2010:107</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securitytracker.com/id?1024031" source="SECTRACK">1024031</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7210" source="OVAL">oval:org.mitre.oval:def:7210</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10258" source="OVAL">oval:org.mitre.oval:def:10258</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html" source="SUSE">SUSE-SR:2010:021</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
      <ref url="http://lists.mysql.com/commits/107532" source="MISC">http://lists.mysql.com/commits/107532</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=53371" source="CONFIRM">http://bugs.mysql.com/bug.php?id=53371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.10a" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.16a" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1a" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.20a" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.24a" />
        <vers num="5.0.27" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.33" />
        <vers num="5.0.37" />
        <vers num="5.0.3a" />
        <vers num="5.0.4" />
        <vers num="5.0.41" />
        <vers num="5.0.45" />
        <vers num="5.0.45b" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" />
        <vers num="5.0.5.0.21" />
        <vers num="5.0.51a" />
        <vers num="5.0.51b" />
        <vers num="5.0.6" />
        <vers num="5.0.67" />
        <vers num="5.0.7" />
        <vers num="5.0.75" />
        <vers num="5.0.77" />
        <vers num="5.0.8" />
        <vers num="5.0.81" />
        <vers num="5.0.82" />
        <vers num="5.0.83" />
        <vers num="5.0.84" />
        <vers num="5.0.85" />
        <vers num="5.0.86" />
        <vers num="5.0.87" />
        <vers num="5.0.88" />
        <vers num="5.0.89" />
        <vers num="5.0.9" />
        <vers num="5.0.90" />
        <vers num="5.0.91" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.15" />
        <vers num="5.1.16" />
        <vers num="5.1.17" />
        <vers num="5.1.2" />
        <vers num="5.1.23" />
        <vers num="5.1.23a" />
        <vers num="5.1.3" />
        <vers num="5.1.30" />
        <vers num="5.1.31" />
        <vers num="5.1.32" />
        <vers num="5.1.33" />
        <vers num="5.1.34" />
        <vers num="5.1.35" />
        <vers num="5.1.36" />
        <vers num="5.1.37" />
        <vers num="5.1.38" />
        <vers num="5.1.39" />
        <vers num="5.1.4" />
        <vers num="5.1.40" />
        <vers num="5.1.41" />
        <vers num="5.1.42" />
        <vers num="5.1.43" />
        <vers num="5.1.44" />
        <vers num="5.1.45" />
        <vers num="5.1.46" />
        <vers num="5.1.5" />
        <vers num="5.1.5a" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1849" published="2010-06-07" name="CVE-2010-1849" modified="2011-01-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/371.html

'CWE-371: State Issues'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:107" source="MANDRIVA">MDVSA-2010:107</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securitytracker.com/id?1024032" source="SECTRACK">1024032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7328" source="OVAL">oval:org.mitre.oval:def:7328</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html" source="SUSE">SUSE-SR:2010:021</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
      <ref url="http://lists.mysql.com/commits/106060" source="MISC">http://lists.mysql.com/commits/106060</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=50974" source="CONFIRM">http://bugs.mysql.com/bug.php?id=50974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.10a" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.16a" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1a" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.20a" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.24a" />
        <vers num="5.0.27" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.33" />
        <vers num="5.0.37" />
        <vers num="5.0.3a" />
        <vers num="5.0.4" />
        <vers num="5.0.41" />
        <vers num="5.0.45" />
        <vers num="5.0.45b" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" />
        <vers num="5.0.5.0.21" />
        <vers num="5.0.51a" />
        <vers num="5.0.51b" />
        <vers num="5.0.6" />
        <vers num="5.0.67" />
        <vers num="5.0.7" />
        <vers num="5.0.75" />
        <vers num="5.0.77" />
        <vers num="5.0.8" />
        <vers num="5.0.81" />
        <vers num="5.0.82" />
        <vers num="5.0.83" />
        <vers num="5.0.84" />
        <vers num="5.0.85" />
        <vers num="5.0.86" />
        <vers num="5.0.87" />
        <vers num="5.0.88" />
        <vers num="5.0.89" />
        <vers num="5.0.9" />
        <vers num="5.0.90" />
        <vers num="5.0.91" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.15" />
        <vers num="5.1.16" />
        <vers num="5.1.17" />
        <vers num="5.1.2" />
        <vers num="5.1.23" />
        <vers num="5.1.23a" />
        <vers num="5.1.3" />
        <vers num="5.1.30" />
        <vers num="5.1.31" />
        <vers num="5.1.32" />
        <vers num="5.1.33" />
        <vers num="5.1.34" />
        <vers num="5.1.35" />
        <vers num="5.1.36" />
        <vers num="5.1.37" />
        <vers num="5.1.38" />
        <vers num="5.1.39" />
        <vers num="5.1.4" />
        <vers num="5.1.40" />
        <vers num="5.1.41" />
        <vers num="5.1.42" />
        <vers num="5.1.43" />
        <vers num="5.1.44" />
        <vers num="5.1.45" />
        <vers num="5.1.46" />
        <vers num="5.1.5" />
        <vers num="5.1.5a" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1850" published="2010-06-07" name="CVE-2010-1850" modified="2011-01-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0442.html" source="REDHAT">RHSA-2010:0442</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:107" source="MANDRIVA">MDVSA-2010:107</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://securitytracker.com/id?1024033" source="SECTRACK">1024033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6693" source="OVAL">oval:org.mitre.oval:def:6693</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10846" source="OVAL">oval:org.mitre.oval:def:10846</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html" source="SUSE">SUSE-SR:2010:019</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=53237" source="CONFIRM">http://bugs.mysql.com/bug.php?id=53237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0" />
        <vers num="5.0.0" edition="alpha" />
        <vers num="5.0.0.0" />
        <vers num="5.0.1" />
        <vers num="5.0.10" />
        <vers num="5.0.10a" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.14" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.16a" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1a" />
        <vers num="5.0.2" />
        <vers num="5.0.20" />
        <vers num="5.0.20a" />
        <vers num="5.0.21" />
        <vers num="5.0.22" />
        <vers num="5.0.23" />
        <vers num="5.0.24" />
        <vers num="5.0.24a" />
        <vers num="5.0.27" />
        <vers num="5.0.3" edition="beta" />
        <vers num="5.0.33" />
        <vers num="5.0.37" />
        <vers num="5.0.3a" />
        <vers num="5.0.4" />
        <vers num="5.0.41" />
        <vers num="5.0.45" />
        <vers num="5.0.45b" />
        <vers num="5.0.4a" />
        <vers num="5.0.5" />
        <vers num="5.0.5.0.21" />
        <vers num="5.0.51a" />
        <vers num="5.0.51b" />
        <vers num="5.0.6" />
        <vers num="5.0.67" />
        <vers num="5.0.7" />
        <vers num="5.0.75" />
        <vers num="5.0.77" />
        <vers num="5.0.8" />
        <vers num="5.0.81" />
        <vers num="5.0.82" />
        <vers num="5.0.83" />
        <vers num="5.0.84" />
        <vers num="5.0.85" />
        <vers num="5.0.86" />
        <vers num="5.0.87" />
        <vers num="5.0.88" />
        <vers num="5.0.89" />
        <vers num="5.0.9" />
        <vers num="5.0.90" />
        <vers num="5.0.91" />
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.15" />
        <vers num="5.1.16" />
        <vers num="5.1.17" />
        <vers num="5.1.2" />
        <vers num="5.1.23" />
        <vers num="5.1.23a" />
        <vers num="5.1.3" />
        <vers num="5.1.30" />
        <vers num="5.1.31" />
        <vers num="5.1.32" />
        <vers num="5.1.33" />
        <vers num="5.1.34" />
        <vers num="5.1.35" />
        <vers num="5.1.36" />
        <vers num="5.1.37" />
        <vers num="5.1.38" />
        <vers num="5.1.39" />
        <vers num="5.1.4" />
        <vers num="5.1.40" />
        <vers num="5.1.41" />
        <vers num="5.1.42" />
        <vers num="5.1.43" />
        <vers num="5.1.44" />
        <vers num="5.1.45" />
        <vers num="5.1.46" />
        <vers num="5.1.5" />
        <vers num="5.1.5a" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1851" published="2010-05-07" name="CVE-2010-1851" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request logging, related to a "cross-site data leakage" issue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cnet.com/8301-31361_1-20004265-254.html" source="MISC">http://www.cnet.com/8301-31361_1-20004265-254.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11757" source="OVAL">oval:org.mitre.oval:def:11757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.1.38.1" />
        <vers num="0.1.38.2" />
        <vers num="0.1.38.4" />
        <vers num="0.1.40.1" />
        <vers num="0.1.42.2" />
        <vers num="0.1.42.3" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1852" published="2010-05-07" name="CVE-2010-1852" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request logging, related to a "cross-site data leakage" issue.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cnet.com/8301-31361_1-20004265-254.html" source="MISC">http://www.cnet.com/8301-31361_1-20004265-254.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1853" published="2010-05-07" name="CVE-2010-1853" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38814" source="BID" patch="1">38814</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0655" source="VUPEN" adv="1">ADV-2010-0655</ref>
      <ref url="http://www.osvdb.org/63066" source="OSVDB">63066</ref>
      <ref url="http://trac.transmissionbt.com/wiki/Changes" source="CONFIRM">http://trac.transmissionbt.com/wiki/Changes</ref>
      <ref url="http://trac.transmissionbt.com/ticket/2965" source="CONFIRM">http://trac.transmissionbt.com/ticket/2965</ref>
      <ref url="http://trac.transmissionbt.com/changeset/10279" source="CONFIRM">http://trac.transmissionbt.com/changeset/10279</ref>
      <ref url="http://secunia.com/advisories/39031" source="SECUNIA" adv="1">39031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transmissionbt" name="transmission">
        <vers num="1.91" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1854" published="2010-05-07" name="CVE-2010-1854" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch &amp; Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  NOTE: this might be resultant from CVE-2010-1855.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39059" source="SECUNIA" adv="1">39059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="pay_per_watch_&amp;_bid_auktions_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1855" published="2010-05-07" name="CVE-2010-1855" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auktion.php in Pay Per Watch &amp; Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57055" source="XF">payperwatch-auktion-sql-injection(57055)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0670" source="VUPEN" adv="1">ADV-2010-0670</ref>
      <ref url="http://www.securityfocus.com/bid/38878" source="BID">38878</ref>
      <ref url="http://www.exploit-db.com/exploits/11816" source="EXPLOIT-DB">11816</ref>
      <ref url="http://secunia.com/advisories/39059" source="SECUNIA" adv="1">39059</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/ppwb-sql.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/ppwb-sql.txt</ref>
      <ref url="http://osvdb.org/63131" source="OSVDB">63131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="pay_per_watch_&amp;_bid_auktions_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1856" published="2010-05-07" name="CVE-2010-1856" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/38907" source="BID">38907</ref>
      <ref url="http://secunia.com/advisories/39043" source="SECUNIA" adv="1">39043</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/repairshop2-xss.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/repairshop2-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realitymedias" name="repairshop2">
        <vers num="1.9.023" edition="-" />
        <vers num="1.9.023" edition="-:trial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1857" published="2010-05-07" name="CVE-2010-1857" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prod parameter in a products.details action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.securityfocus.com/bid/38907" source="BID">38907</ref>
      <ref url="http://secunia.com/advisories/39043" source="SECUNIA" adv="1">39043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realitymedias" name="repairshop2">
        <vers num="1.9.023" edition="-" />
        <vers num="1.9.023" edition="-:trial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1858" published="2010-05-07" name="CVE-2010-1858" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57108" source="XF">smestorage-index-file-include(57108)</ref>
      <ref url="http://www.securityfocus.com/bid/38911" source="BID">38911</ref>
      <ref url="http://www.exploit-db.com/exploits/11853" source="EXPLOIT-DB">11853</ref>
      <ref url="http://secunia.com/advisories/39071" source="SECUNIA" adv="1">39071</ref>
      <ref url="http://packetstormsecurity.org/1003-exploits/joomlasmestorage-lfi.txt" source="MISC">http://packetstormsecurity.org/1003-exploits/joomlasmestorage-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gelembjuk" name="com_smestorage">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1859" published="2010-05-07" name="CVE-2010-1859" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39962" source="BID">39962</ref>
      <ref url="http://php-security.org/2010/05/06/mops-2010-011-deluxebb-newthread-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/06/mops-2010-011-deluxebb-newthread-sql-injection-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deluxebb" name="deluxebb">
        <vers num="1.0" />
        <vers num="1.05" />
        <vers num="1.06" />
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1860" published="2010-05-07" name="CVE-2010-1860" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/06/mops-2010-010-php-html_entity_decode-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/06/mops-2010-010-php-html_entity_decode-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1861" published="2010-05-07" name="CVE-2010-1861" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/05/mops-2010-009-php-shm_put_var-already-freed-resource-access-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/05/mops-2010-009-php-shm_put_var-already-freed-resource-access-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1862" published="2010-05-07" name="CVE-2010-1862" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/04/mops-2010-008-php-chunk_split-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/04/mops-2010-008-php-chunk_split-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1863" published="2010-05-07" name="CVE-2010-1863" modified="2010-05-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the shoutbox module (modules/shoutbox.php) in ClanTiger 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the s_email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/04/mops-2010-007-clantiger-shoutbox-module-s_email-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/04/mops-2010-007-clantiger-shoutbox-module-s_email-sql-injection-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clantiger" name="clantiger">
        <vers num="0.2" edition="alpha" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1864" published="2010-05-07" name="CVE-2010-1864" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/03/mops-2010-006-php-addcslashes-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/03/mops-2010-006-php-addcslashes-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1865" published="2010-05-07" name="CVE-2010-1865" modified="2010-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://trac.clansphere.de/csp/changeset/3808/" source="CONFIRM" patch="1">http://trac.clansphere.de/csp/changeset/3808/</ref>
      <ref url="http://trac.clansphere.de/csp/changeset/3803/" source="CONFIRM" patch="1">http://trac.clansphere.de/csp/changeset/3803/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58311" source="XF">clansphere-captcha-sql-injection(58311)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1066" source="VUPEN">ADV-2010-1066</ref>
      <ref url="http://www.securityfocus.com/bid/39896" source="BID">39896</ref>
      <ref url="http://www.csphere.eu/index/news/view/id/487/start/0" source="CONFIRM">http://www.csphere.eu/index/news/view/id/487/start/0</ref>
      <ref url="http://secunia.com/advisories/39685" source="SECUNIA">39685</ref>
      <ref url="http://php-security.org/2010/05/03/mops-2010-005-clansphere-mysql-driver-generic-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/03/mops-2010-005-clansphere-mysql-driver-generic-sql-injection-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/03/mops-2010-004-clansphere-captcha-generator-blind-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/03/mops-2010-004-clansphere-captcha-generator-blind-sql-injection-vulnerability/index.html</ref>
      <ref url="http://osvdb.org/64321" source="OSVDB">64321</ref>
      <ref url="http://osvdb.org/64320" source="OSVDB">64320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="csphere" name="clansphere">
        <vers num="2007" edition="rc1" />
        <vers num="2007" edition="rc2" />
        <vers num="2007" edition="rc3" />
        <vers num="2007.0" />
        <vers num="2007.1" />
        <vers num="2007.2" />
        <vers num="2007.2.1" />
        <vers num="2007.3" />
        <vers num="2007.3.1" />
        <vers num="2007.4" />
        <vers num="2007.4.1" />
        <vers num="2007.4.2" />
        <vers num="2007.4.3" />
        <vers num="2007.4.4" />
        <vers num="2008.0" />
        <vers num="2008.1" />
        <vers num="2008.2" />
        <vers num="2008.2.1" />
        <vers num="2009.0" edition="rc1" />
        <vers num="2009.0" edition="rc2" />
        <vers num="2009.0" edition="rc3" />
        <vers num="2009.0.1" />
        <vers num="2009.0.2" />
        <vers prev="1" num="2009.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1866" published="2010-05-07" name="CVE-2010-1866" modified="2010-09-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/02/mops-2010-003-php-dechunk-filter-signed-comparison-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/02/mops-2010-003-php-dechunk-filter-signed-comparison-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1867" published="2010-05-07" name="CVE-2010-1867" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/attachments.php in Campsite 3.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58285" source="XF">campsite-articleid-sql-injection(58285)</ref>
      <ref url="http://www.securityfocus.com/bid/39862" source="BID">39862</ref>
      <ref url="http://www.campware.org/en/camp/campsite_news/832/" source="CONFIRM">http://www.campware.org/en/camp/campsite_news/832/</ref>
      <ref url="http://secunia.com/advisories/39580" source="SECUNIA">39580</ref>
      <ref url="http://php-security.org/2010/05/01/mops-2010-002-campsite-tinymce-article-attachment-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/01/mops-2010-002-campsite-tinymce-article-attachment-sql-injection-vulnerability/index.html</ref>
      <ref url="http://osvdb.org/64215" source="OSVDB">64215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="campware.org" name="campsite">
        <vers num="2.2.2" />
        <vers num="2.3.3" />
        <vers num="2.4.3" />
        <vers num="2.5.2" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.9" />
        <vers num="2.7.0" edition="rc5" />
        <vers num="3.0.3" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3.0" edition="rc1" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers prev="1" num="3.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1868" published="2010-05-07" name="CVE-2010-1868" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, which triggers access of uninitialized memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/07/mops-submission-03-sqlite_single_query-sqlite_array_query-uninitialized-memory-usage/index.html" source="MISC">http://php-security.org/2010/05/07/mops-submission-03-sqlite_single_query-sqlite_array_query-uninitialized-memory-usage/index.html</ref>
      <ref url="http://php-security.org/2010/05/07/mops-2010-013-php-sqlite_array_query-uninitialized-memory-usage-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/07/mops-2010-013-php-sqlite_array_query-uninitialized-memory-usage-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/07/mops-2010-012-php-sqlite_single_query-uninitialized-memory-usage-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/07/mops-2010-012-php-sqlite_single_query-uninitialized-memory-usage-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1869" published="2010-05-12" name="CVE-2010-1869" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1195" source="VUPEN">ADV-2010-1195</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1138" source="VUPEN">ADV-2010-1138</ref>
      <ref url="http://www.ubuntu.com/usn/USN-961-1" source="UBUNTU">USN-961-1</ref>
      <ref url="http://www.securitytracker.com/id?1024003" source="SECTRACK">1024003</ref>
      <ref url="http://www.securityfocus.com/bid/40103" source="BID">40103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511243/100/0/threaded" source="BUGTRAQ">20100512 Multiple memory corruption vulnerabilities in Ghostscript</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:102" source="MANDRIVA">MDVSA-2010:102</ref>
      <ref url="http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.html" source="MISC">http://www.checkpoint.com/defense/advisories/public/2010/cpai-10-May.html</ref>
      <ref url="http://secunia.com/advisories/40580" source="SECUNIA">40580</ref>
      <ref url="http://secunia.com/advisories/39753" source="SECUNIA">39753</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="artifex" name="gpl_ghostscript">
        <vers num="8.64" />
        <vers num="8.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1870" published="2010-08-17" name="CVE-2010-1870" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/41592" source="BID">41592</ref>
      <ref url="http://www.osvdb.org/66280" source="OSVDB">66280</ref>
      <ref url="http://www.exploit-db.com/exploits/14360" source="EXPLOIT-DB">14360</ref>
      <ref url="http://struts.apache.org/2.2.1/docs/s2-005.html" source="CONFIRM">http://struts.apache.org/2.2.1/docs/s2-005.html</ref>
      <ref url="http://securityreason.com/securityalert/8345" source="SREASON">8345</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Jul/183" source="FULLDISC">20100713 CVE-2010-1870: Struts2 remote commands execution</ref>
      <ref url="http://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16" source="CONFIRM" adv="1">http://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16</ref>
      <ref url="http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html" source="MISC">http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="struts">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.11.1" />
        <vers num="2.0.11.2" />
        <vers num="2.0.12" />
        <vers num="2.0.13" />
        <vers num="2.0.14" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.8" />
        <vers num="2.1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1871" published="2010-08-05" name="CVE-2010-1871" modified="2010-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL.  NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=615956" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=615956</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/60794" source="XF">seam-expressions-code-execution(60794)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1929" source="VUPEN" adv="1">ADV-2010-1929</ref>
      <ref url="http://www.securitytracker.com/id?1024253" source="SECTRACK">1024253</ref>
      <ref url="http://www.securityfocus.com/bid/41994" source="BID">41994</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0564.html" source="REDHAT">RHSA-2010:0564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1872" published="2010-05-12" name="CVE-2010-1872" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.xenuser.org/documents/security/flashcard_xss.txt" source="MISC">http://www.xenuser.org/documents/security/flashcard_xss.txt</ref>
      <ref url="http://www.securityfocus.com/bid/39648" source="BID">39648</ref>
      <ref url="http://secunia.com/advisories/39484" source="SECUNIA" adv="1">39484</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/flashcard-xss.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/flashcard-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tufat" name="flashcard">
        <vers num="2.6.5" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1873" published="2010-05-12" name="CVE-2010-1873" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57774" source="XF">jvehicles-index-sql-injection(57774)</ref>
      <ref url="http://www.securityfocus.com/bid/39409" source="BID">39409</ref>
      <ref url="http://www.osvdb.org/63669" source="OSVDB">63669</ref>
      <ref url="http://www.exploit-db.com/exploits/12190" source="EXPLOIT-DB">12190</ref>
      <ref url="http://secunia.com/advisories/39401" source="SECUNIA" adv="1">39401</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajvehicles-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajvehicles-sql.txt</ref>
      <ref url="http://indonesiancoder.org/joomla-component-jvehicles-aid-sql-injection-vulnerability" source="MISC">http://indonesiancoder.org/joomla-component-jvehicles-aid-sql-injection-vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jvehicles" name="com_jvehicles">
        <vers num="1.0" />
        <vers num="2.0" />
        <vers num="2.1111" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1874" published="2010-05-12" name="CVE-2010-1874" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57765" source="XF">properties-index-sql-injection(57765)</ref>
      <ref url="http://www.securityfocus.com/bid/39374" source="BID">39374</ref>
      <ref url="http://www.exploit-db.com/exploits/12136" source="EXPLOIT-DB">12136</ref>
      <ref url="http://secunia.com/advisories/39074" source="SECUNIA" adv="1">39074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="com-property" name="com_properties">
        <vers num="3.1.22-03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1875" published="2010-05-12" name="CVE-2010-1875" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57110" source="XF">realestate-index-file-include(57110)</ref>
      <ref url="http://www.securityfocus.com/bid/38912" source="BID">38912</ref>
      <ref url="http://www.osvdb.org/63143" source="OSVDB">63143</ref>
      <ref url="http://www.exploit-db.com/exploits/11851" source="EXPLOIT-DB">11851</ref>
      <ref url="http://secunia.com/advisories/39074" source="SECUNIA" adv="1">39074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="com-property" name="com_properties">
        <vers num="3.1.22-03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1876" published="2010-05-12" name="CVE-2010-1876" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58049" source="XF">ajshopping-index-sql-injection(58049)</ref>
      <ref url="http://www.exploit-db.com/exploits/12349" source="EXPLOIT-DB">12349</ref>
      <ref url="http://secunia.com/advisories/39551" source="SECUNIA" adv="1">39551</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/ajshoppingcart-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/ajshoppingcart-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ajsquare" name="aj_shopping_cart">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1877" published="2010-05-12" name="CVE-2010-1877" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57977" source="XF">jtmreseller-author-sql-injection(57977)</ref>
      <ref url="http://www.securityfocus.com/bid/39584" source="BID">39584</ref>
      <ref url="http://www.exploit-db.com/exploits/12306" source="EXPLOIT-DB">12306</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajtmreseller-sql.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajtmreseller-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jtmreseller" name="com_jtm">
        <vers num="1.9" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1878" published="2010-05-12" name="CVE-2010-1878" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58031" source="XF">orgchart-index-file-include(58031)</ref>
      <ref url="http://www.securityfocus.com/bid/39606" source="BID">39606</ref>
      <ref url="http://www.exploit-db.com/exploits/12317" source="EXPLOIT-DB">12317</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaorgchart-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaorgchart-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blueflyingfish.no-ip" name="com_orgchart">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1879" published="2010-06-08" name="CVE-2010-1879" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "Media Decompression Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx" source="MS" patch="1" adv="1">MS10-033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7517" source="OVAL">oval:org.mitre.oval:def:7517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="9.0" />
        <vers num="9.0a" />
        <vers num="9.0b" />
        <vers num="9.0c" />
      </prod>
      <prod vendor="microsoft" name="windows_media_encoder">
        <vers num="9" edition="-" />
        <vers num="9" edition="-:x86" />
        <vers num="9" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_media_format_runtime">
        <vers num="11" />
        <vers num="9" />
        <vers num="9.5" edition="" />
        <vers num="9.5" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1880" published="2010-06-08" name="CVE-2010-1880" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-033.mspx" source="MS" patch="1" adv="1">MS10-033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6641" source="OVAL">oval:org.mitre.oval:def:6641</ref>
      <ref url="http://osvdb.org/65222" source="OSVDB">65222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="9.0" />
        <vers num="9.0a" />
        <vers num="9.0b" />
        <vers num="9.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1881" published="2010-07-15" name="CVE-2010-1881" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-194A.html" source="CERT">TA10-194A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-044.mspx" source="MS" patch="1" adv="1">MS10-044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11756" source="OVAL">oval:org.mitre.oval:def:11756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="access">
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1882" published="2010-08-11" name="CVE-2010-1882" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-052.mspx" source="MS" patch="1" adv="1">MS10-052</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11585" source="OVAL">oval:org.mitre.oval:def:11585</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1883" published="2010-10-13" name="CVE-2010-1883" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-285A.html" source="CERT">TA10-285A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-076.mspx" source="MS" patch="1" adv="1">MS10-076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6881" source="OVAL">oval:org.mitre.oval:def:6881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1885" published="2010-06-15" name="CVE-2010-1885" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx

"customers running Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2, are not vulnerable to this issue, or at risk of attack."</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-194A.html" source="CERT">TA10-194A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/578319" source="CERT-VN">VU#578319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59267" source="XF">ms-win-helpctr-command-execution(59267)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1417" source="VUPEN" adv="1">ADV-2010-1417</ref>
      <ref url="http://www.securitytracker.com/id?1024084" source="SECTRACK">1024084</ref>
      <ref url="http://www.securityfocus.com/bid/40725" source="BID">40725</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511783/100/0/threaded" source="BUGTRAQ">20100610 Re: Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511774/100/0/threaded" source="BUGTRAQ">20100609 Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-042.mspx" source="MS">MS10-042</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/2219475.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/2219475.mspx</ref>
      <ref url="http://www.exploit-db.com/exploits/13808" source="EXPLOIT-DB">13808</ref>
      <ref url="http://secunia.com/advisories/40076" source="SECUNIA" adv="1">40076</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11733" source="OVAL">oval:org.mitre.oval:def:11733</ref>
      <ref url="http://blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/b/srd/archive/2010/06/10/help-and-support-center-vulnerability-full-disclosure-posting.aspx</ref>
      <ref url="http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx" source="MISC">http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0197.html" source="FULLDISC">20100609 Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1886" published="2010-08-16" name="CVE-2010-1886" modified="2010-08-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature.  NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.microsoft.com/kb/982316" source="MSKB" patch="1" adv="1">982316</ref>
      <ref url="http://support.microsoft.com/kb/2264072" source="MSKB" patch="1" adv="1">2264072</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/2264072.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/2264072.mspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="r2" edition="" />
        <vers num="r2" edition=":x64" />
        <vers num="r2" edition=":itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1887" published="2010-08-11" name="CVE-2010-1887" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:N/I:N/A:C)" CVSS_score="4.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="2.7" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx" source="MS" patch="1" adv="1">MS10-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11020" source="OVAL">oval:org.mitre.oval:def:11020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1888" published="2010-08-11" name="CVE-2010-1888" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Kernel Data Initialization Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-047.mspx" source="MS" patch="1" adv="1">MS10-047</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11825" source="OVAL">oval:org.mitre.oval:def:11825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1889" published="2010-08-11" name="CVE-2010-1889" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-047.mspx" source="MS" patch="1" adv="1">MS10-047</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11044" source="OVAL">oval:org.mitre.oval:def:11044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="" />
        <vers num="-" edition=":itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1890" published="2010-08-11" name="CVE-2010-1890" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-047.mspx" source="MS" patch="1" adv="1">MS10-047</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11789" source="OVAL">oval:org.mitre.oval:def:11789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="" />
        <vers num="-" edition=":itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1891" published="2010-09-15" name="CVE-2010-1891" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-069.mspx" source="MS" patch="1" adv="1">MS10-069</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7536" source="OVAL">oval:org.mitre.oval:def:7536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1892" published="2010-08-11" name="CVE-2010-1892" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-058.mspx" source="MS" patch="1" adv="1">MS10-058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11845" source="OVAL">oval:org.mitre.oval:def:11845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1893" published="2010-08-11" name="CVE-2010-1893" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-058.mspx" source="MS" patch="1" adv="1">MS10-058</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12087" source="OVAL">oval:org.mitre.oval:def:12087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1894" published="2010-08-11" name="CVE-2010-1894" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx" source="MS" patch="1" adv="1">MS10-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11769" source="OVAL">oval:org.mitre.oval:def:11769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1895" published="2010-08-11" name="CVE-2010-1895" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx" source="MS" patch="1" adv="1">MS10-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11844" source="OVAL">oval:org.mitre.oval:def:11844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1896" published="2010-08-11" name="CVE-2010-1896" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx" source="MS" patch="1" adv="1">MS10-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12006" source="OVAL">oval:org.mitre.oval:def:12006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1897" published="2010-08-11" name="CVE-2010-1897" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx" source="MS" patch="1" adv="1">MS10-048</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11663" source="OVAL">oval:org.mitre.oval:def:11663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1898" published="2010-08-11" name="CVE-2010-1898" modified="2011-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-060.mspx" source="MS" patch="1" adv="1">MS10-060</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12033" source="OVAL">oval:org.mitre.oval:def:12033</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="2.0" edition="sp1" />
        <vers num="2.0" edition="sp2" />
        <vers num="3.5" edition="sp1" />
        <vers num="3.5.1" />
      </prod>
      <prod vendor="microsoft" name="silverlight">
        <vers num="2.0.31005.00" />
        <vers num="2.0.40115.00" />
        <vers num="3.0.40624.00" />
        <vers num="3.0.40723.0" />
        <vers prev="1" num="3.0.40818.0" />
        <vers prev="1" num="3.0.50106.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1899" published="2010-09-15" name="CVE-2010-1899" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS10-065.mspx

'ASP pages are prohibited by default on IIS 6.0.  - The vulnerability is only exploitable when the ASP script writes parameters from the request in the response.'</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-065.mspx" source="MS" patch="1" adv="1">MS10-065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7127" source="OVAL">oval:org.mitre.oval:def:7127</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="7.0" />
        <vers num="7.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1900" published="2010-08-11" name="CVE-2010-1900" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not properly handle malformed records in a Word file, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, aka "Word Record Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx" source="MS" patch="1" adv="1">MS10-056</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11490" source="OVAL">oval:org.mitre.oval:def:11490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1901" published="2010-08-11" name="CVE-2010-1901" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly handle unspecified properties in rich text data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka "Word RTF Parsing Engine Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx" source="MS" patch="1" adv="1">MS10-056</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11612" source="OVAL">oval:org.mitre.oval:def:11612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1902" published="2010-08-11" name="CVE-2010-1902" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via unspecified properties in the data in a crafted RTF document, aka "Word RTF Parsing Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx" source="MS" patch="1" adv="1">MS10-056</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11472" source="OVAL">oval:org.mitre.oval:def:11472</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1903" published="2010-08-11" name="CVE-2010-1903" modified="2010-09-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-222A.html" source="CERT">TA10-222A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx" source="MS" patch="1" adv="1">MS10-056</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12039" source="OVAL">oval:org.mitre.oval:def:12039</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="word">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1904" published="2010-06-07" name="CVE-2010-1904" modified="2011-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in EMC RSA Key Manager (RKM) C Client 1.5.x allows user-assisted remote attackers to execute arbitrary SQL commands via the metadata section of encrypted key data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59133" source="XF">rsakey-metadata-sql-injection(59133)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0206" source="VUPEN">ADV-2011-0206</ref>
      <ref url="http://www.securitytracker.com/id?1024989" source="SECTRACK">1024989</ref>
      <ref url="http://www.securitytracker.com/id?1024059" source="SECTRACK">1024059</ref>
      <ref url="http://www.securityfocus.com/bid/40553" source="BID">40553</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511654/100/0/threaded" source="BUGTRAQ">20100603 RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )</ref>
      <ref url="http://secunia.com/advisories/43057" source="SECUNIA">43057</ref>
      <ref url="http://seclists.org/bugtraq/2011/Jan/138" source="BUGTRAQ">20110121 ESA-2011-001: RSA, The Security Division of EMC, addresses RKM 1.5 C Client SQL Injection Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0078.html" source="FULLDISC">20100603 RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="rsa_key_manager_client">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1905" published="2010-05-12" name="CVE-2010-1905" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf" source="CONFIRM" patch="1" adv="1">http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/39999" source="BID">39999</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
      <ref url="http://secunia.com/advisories/39740" source="SECUNIA" adv="1">39740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1906" published="2010-05-12" name="CVE-2010-1906" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timestamp field to validate input to the \\.\pipe\__RepairService_pipe__company named pipe, which allows remote authenticated users to execute arbitrary code by obtaining the current time from (1) tcpip.sys or (2) an SMB2 service.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf" source="CONFIRM" patch="1" adv="1">http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
      <ref url="http://secunia.com/advisories/39752" source="SECUNIA" adv="1">39752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_repair_manager">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_activation">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_agent">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1907" published="2010-05-12" name="CVE-2010-1907" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to discover the username of the client user, and consequently determine a pathname to a certain user directory, via a call to the GetUserName method.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1908" published="2010-05-12" name="CVE-2010-1908" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1) HTTPDownloadFile or (2) HTTPGetFile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
      <ref url="http://secunia.com/advisories/39751" source="SECUNIA" adv="1">39751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1909" published="2010-05-12" name="CVE-2010-1909" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in the RunCmd method in the SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to execute arbitrary code via vectors involving "CreateProcess params." NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
      <ref url="http://secunia.com/advisories/39751" source="SECUNIA" adv="1">39751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1910" published="2010-05-12" name="CVE-2010-1910" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf" source="CONFIRM" patch="1" adv="1">http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/40003" source="BID">40003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
      <ref url="http://secunia.com/advisories/39740" source="SECUNIA" adv="1">39740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1911" published="2010-05-12" name="CVE-2010-1911" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf" source="CONFIRM" patch="1" adv="1">http://www.consona.com/Content/CRM/Support/SecurityBulletin_April2010.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58608" source="XF">consona-sdcwebsecurebase-code-exec(58608)</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1912" published="2010-05-12" name="CVE-2010-1912" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass intended restrictions on ActiveX execution via "instantiation/free attacks."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58607" source="XF">consona-sdcwebsecurebase-sec-bypass(58607)</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1913" published="2010-05-12" name="CVE-2010-1913" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/602801" source="CERT-VN" patch="1">VU#602801</ref>
      <ref url="http://www.wintercore.com/downloads/rootedcon_0day.pdf" source="MISC">http://www.wintercore.com/downloads/rootedcon_0day.pdf</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511176/100/0/threaded" source="BUGTRAQ">20100507 [Wintercore Research] Consona Products - Multiple vulnerabilities</ref>
      <ref url="http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html" source="MISC">http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="consona" name="consona_dynamic_agent">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:enterprise" />
        <vers num="-" edition="-:support" />
        <vers num="-" edition="-:marketing" />
      </prod>
      <prod vendor="consona" name="consona_live_assistance">
        <vers num="" />
      </prod>
      <prod vendor="consona" name="consona_subscriber_assistance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1914" published="2010-05-12" name="CVE-2010-1914" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58587" source="XF">php-zendengine-info-disclosure(58587)</ref>
      <ref url="http://www.php-security.org/2010/05/08/mops-2010-016-php-zend_sr-opcode-interruption-address-information-leak-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/08/mops-2010-016-php-zend_sr-opcode-interruption-address-information-leak-vulnerability/index.html</ref>
      <ref url="http://www.php-security.org/2010/05/08/mops-2010-015-php-zend_sl-opcode-interruption-address-information-leak-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/08/mops-2010-015-php-zend_sl-opcode-interruption-address-information-leak-vulnerability/index.html</ref>
      <ref url="http://www.php-security.org/2010/05/08/mops-2010-014-php-zend_bw_xor-opcode-interruption-address-information-leak-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/08/mops-2010-014-php-zend_bw_xor-opcode-interruption-address-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1915" published="2010-05-12" name="CVE-2010-1915" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58586" source="XF">php-pregquote-information-disclosure(58586)</ref>
      <ref url="http://www.php-security.org/2010/05/09/mops-2010-017-php-preg_quote-interruption-information-leak-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/09/mops-2010-017-php-preg_quote-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1916" published="2010-05-12" name="CVE-2010-1916" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function.  NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=591701" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=591701</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1401" source="VUPEN">ADV-2010-1401</ref>
      <ref url="http://www.securityfocus.com/bid/40033" source="BID">40033</ref>
      <ref url="http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html</ref>
      <ref url="http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html</ref>
      <ref url="http://trac.xinha.org/ticket/1518" source="CONFIRM">http://trac.xinha.org/ticket/1518</ref>
      <ref url="http://secunia.com/advisories/40124" source="SECUNIA">40124</ref>
      <ref url="http://secunia.com/advisories/39782" source="SECUNIA">39782</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042577.html" source="FEDORA">FEDORA-2010-9320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="s9y" name="serendipity">
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" edition="pl1" />
        <vers num="0.6" edition="pl3" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
      </prod>
      <prod vendor="xinha" name="wysiwyg_editor">
        <vers num="0.9" edition="beta" />
        <vers num="0.91" edition="beta" />
        <vers num="0.92" edition="beta" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" edition="beta" />
        <vers num="0.96" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1917" published="2010-05-12" name="CVE-2010-1917" modified="2011-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack consumption vulnerability in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (PHP crash) via a crafted first argument to the fnmatch function, as demonstrated using a long string.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58585" source="XF">php-fnmatchfunction-dos(58585)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3081" source="VUPEN">ADV-2010-3081</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0919.html" source="REDHAT">RHSA-2010:0919</ref>
      <ref url="http://www.php-security.org/2010/05/11/mops-2010-021-php-fnmatch-stack-exhaustion-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/11/mops-2010-021-php-fnmatch-stack-exhaustion-vulnerability/index.html</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2089" source="DEBIAN">DSA-2089</ref>
      <ref url="http://secunia.com/advisories/42410" source="SECUNIA">42410</ref>
      <ref url="http://secunia.com/advisories/40860" source="SECUNIA">40860</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130331363227777&amp;w=2" source="HP">SSRT100409</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130331363227777&amp;w=2" source="HP">HPSBMA02662</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1918" published="2010-05-12" name="CVE-2010-1918" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1101" source="VUPEN" adv="1">ADV-2010-1101</ref>
      <ref url="http://www.securityfocus.com/bid/40032" source="BID">40032</ref>
      <ref url="http://www.php-security.org/2010/05/09/mops-2010-018-efront-ask_chat-chatrooms_id-sql-injection-vulnerability/index.html" source="MISC">http://www.php-security.org/2010/05/09/mops-2010-018-efront-ask_chat-chatrooms_id-sql-injection-vulnerability/index.html</ref>
      <ref url="http://secunia.com/advisories/39728" source="SECUNIA" adv="1">39728</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/MOPS-2010-018.pdf" source="MISC">http://packetstormsecurity.org/1005-exploits/MOPS-2010-018.pdf</ref>
      <ref url="http://osvdb.org/64506" source="OSVDB">64506</ref>
    </refs>
    <vuln_soft>
      <prod vendor="efrontlearning" name="efront">
        <vers num="3.1.0" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.5.0" edition="beta1" />
        <vers num="3.5.0" edition="beta2" />
        <vers num="3.5.0" edition="beta3" />
        <vers num="3.5.0" edition="beta4" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers prev="1" num="3.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1919" published="2010-05-28" name="CVE-2010-1919" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1253" source="VUPEN" adv="1">ADV-2010-1253</ref>
      <ref url="http://www.securityfocus.com/bid/40390" source="BID">40390</ref>
      <ref url="http://www.packetstormsecurity.org/1005-advisories/ESA-2010-007.txt" source="MISC">http://www.packetstormsecurity.org/1005-advisories/ESA-2010-007.txt</ref>
      <ref url="http://securitytracker.com/id?1024036" source="SECTRACK">1024036</ref>
      <ref url="http://secunia.com/advisories/39919" source="SECUNIA" adv="1">39919</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/current/0254.html" source="BUGTRAQ">20100526 ESA-2010-007: EMC Avamar Denial Of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="avamar">
        <vers num="4.1" />
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1920" published="2010-05-12" name="CVE-2010-1920" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1059" source="VUPEN" adv="1">ADV-2010-1059</ref>
      <ref url="http://www.securityfocus.com/bid/39887" source="BID">23505</ref>
      <ref url="http://www.exploit-db.com/exploits/12486" source="EXPLOIT-DB">12486</ref>
      <ref url="http://secunia.com/advisories/39673" source="SECUNIA" adv="1">39673</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/openmairie-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/openmairie-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openannuaire">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1921" published="2010-05-12" name="CVE-2010-1921" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) annuaire.class.php, (2) droit.class.php, (3) collectivite.class.php, (4) profil.class.php, (5) direction.class.php, (6) service.class.php, (7) directiongenerale.class.php, and (8) utilisateur.class.php in obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1059" source="VUPEN" adv="1">ADV-2010-1059</ref>
      <ref url="http://www.securityfocus.com/bid/39887" source="BID">39887</ref>
      <ref url="http://www.osvdb.org/64184" source="OSVDB">64184</ref>
      <ref url="http://www.osvdb.org/64182" source="OSVDB">64182</ref>
      <ref url="http://www.osvdb.org/64181" source="OSVDB">64181</ref>
      <ref url="http://www.osvdb.org/64180" source="OSVDB">64180</ref>
      <ref url="http://www.osvdb.org/64179" source="OSVDB">64179</ref>
      <ref url="http://www.osvdb.org/64178" source="OSVDB">64178</ref>
      <ref url="http://www.osvdb.org/64177" source="OSVDB">64177</ref>
      <ref url="http://www.osvdb.org/64176" source="OSVDB">64176</ref>
      <ref url="http://www.exploit-db.com/exploits/12486" source="EXPLOIT-DB">12486</ref>
      <ref url="http://secunia.com/advisories/39673" source="SECUNIA" adv="1">39673</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/openmairie-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/openmairie-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openannuaire">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1922" published="2010-05-12" name="CVE-2010-1922" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php, and (4) layoutParser.php in lib/layout/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1120" source="VUPEN" adv="1">ADV-2010-1120</ref>
      <ref url="http://www.securityfocus.com/bid/40049" source="BID">40049</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511222/100/0/threaded" source="BUGTRAQ">20100511 29o3 CMS (LibDir) Multiple Remote File Inclusion Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/12558" source="EXPLOIT-DB">12558</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/29o3cms-rfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/29o3cms-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="29o3_cms" name="29o3_cms">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1923" published="2010-05-12" name="CVE-2010-1923" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58583" source="XF">socialnetworking-user-sql-injection(58583)</ref>
      <ref url="http://secunia.com/advisories/39761" source="SECUNIA" adv="1">39761</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/web20snfcs-sql.txt</ref>
      <ref url="http://osvdb.org/64513" source="OSVDB">64513</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="web_social_network_freunde_community">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1924" published="2010-05-12" name="CVE-2010-1924" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58392" source="XF">liveshopping-index-sql-injection(58392)</ref>
      <ref url="http://www.securityfocus.com/bid/40040" source="BID">40040</ref>
      <ref url="http://www.exploit-db.com/exploits/12545" source="EXPLOIT-DB">12545</ref>
      <ref url="http://secunia.com/advisories/39718" source="SECUNIA" adv="1">39718</ref>
      <ref url="http://osvdb.org/64512" source="OSVDB">64512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpscripte24" name="live_shopping_multi_portal_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1925" published="2010-05-12" name="CVE-2010-1925" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1117" source="VUPEN" adv="1">ADV-2010-1117</ref>
      <ref url="http://www.securityfocus.com/bid/40030" source="BID">40030</ref>
      <ref url="http://www.exploit-db.com/exploits/12552" source="EXPLOIT-DB">12552</ref>
      <ref url="http://secunia.com/advisories/20464" source="SECUNIA" adv="1">20464</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/teknoportal-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/teknoportal-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rifat_kurban" name="tekno.portal">
        <vers num="0.1b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1926" published="2010-05-12" name="CVE-2010-1926" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1003" source="VUPEN" adv="1">ADV-2010-1003</ref>
      <ref url="http://www.osvdb.org/64201" source="OSVDB">64201</ref>
      <ref url="http://www.exploit-db.com/exploits/12398" source="EXPLOIT-DB">12398</ref>
      <ref url="http://secunia.com/advisories/39624" source="SECUNIA" adv="1">39624</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/opencourrier-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/opencourrier-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="opencourrier">
        <vers num="2.02" />
        <vers num="2.03" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1927" published="2010-05-12" name="CVE-2010-1927" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) bible.class.php, (2) dossier.class.php, (3) service.class.php, (4) collectivite.class.php, (5) droit.class.php, (6) tache.class.php, (7) emetteur.class.php, (8) utilisateur.class.php, (9) courrier.recherche.tab.class.php, and (10) profil.class.php in obj/.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1003" source="VUPEN" adv="1">ADV-2010-1003</ref>
      <ref url="http://www.osvdb.org/64210" source="OSVDB">64210</ref>
      <ref url="http://www.osvdb.org/64209" source="OSVDB">64209</ref>
      <ref url="http://www.osvdb.org/64208" source="OSVDB">64208</ref>
      <ref url="http://www.osvdb.org/64207" source="OSVDB">64207</ref>
      <ref url="http://www.osvdb.org/64206" source="OSVDB">64206</ref>
      <ref url="http://www.osvdb.org/64205" source="OSVDB">64205</ref>
      <ref url="http://www.osvdb.org/64204" source="OSVDB">64204</ref>
      <ref url="http://www.osvdb.org/64203" source="OSVDB">64203</ref>
      <ref url="http://www.osvdb.org/64202" source="OSVDB">64202</ref>
      <ref url="http://www.exploit-db.com/exploits/12398" source="EXPLOIT-DB">12398</ref>
      <ref url="http://secunia.com/advisories/39624" source="SECUNIA" adv="1">39624</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/opencourrier-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/opencourrier-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="opencourrier">
        <vers num="2.02" />
        <vers num="2.03" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1928" published="2010-05-12" name="CVE-2010-1928" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58090" source="XF">openpresse-soustab-file-include(58090)</ref>
      <ref url="http://www.osvdb.org/64185" source="OSVDB">64185</ref>
      <ref url="http://www.exploit-db.com/exploits/12365" source="EXPLOIT-DB">12365</ref>
      <ref url="http://secunia.com/advisories/39606" source="SECUNIA" adv="1">39606</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openplanning-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openplanning-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openplanning">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1929" published="2010-06-28" name="CVE-2010-1929" modified="2010-06-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59694" source="XF">imanager-class-bo(59694)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1575" source="VUPEN" adv="1">ADV-2010-1575</ref>
      <ref url="http://www.securityfocus.com/bid/40480" source="BID">40480</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511983/100/0/threaded" source="BUGTRAQ">20100623 CORE-2010-0316 - Novell iManager Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/65737" source="OSVDB">65737</ref>
      <ref url="http://www.exploit-db.com/exploits/14010" source="EXPLOIT-DB">14010</ref>
      <ref url="http://www.coresecurity.com/content/novell-imanager-buffer-overflow-off-by-one-vulnerabilities" source="MISC">http://www.coresecurity.com/content/novell-imanager-buffer-overflow-off-by-one-vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024152" source="SECTRACK">1024152</ref>
      <ref url="http://secunia.com/advisories/40281" source="SECUNIA" adv="1">40281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="imanager">
        <vers num="2.7.0" />
        <vers num="2.7.3" edition="ftf2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1930" published="2010-06-28" name="CVE-2010-1930" modified="2010-06-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59695" source="XF">imanager-tree-dos(59695)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1575" source="VUPEN" adv="1">ADV-2010-1575</ref>
      <ref url="http://www.securityfocus.com/bid/40485" source="BID">40485</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511983/100/0/threaded" source="BUGTRAQ">20100623 CORE-2010-0316 - Novell iManager Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/65738" source="OSVDB">65738</ref>
      <ref url="http://www.exploit-db.com/exploits/14010" source="EXPLOIT-DB">14010</ref>
      <ref url="http://www.coresecurity.com/content/novell-imanager-buffer-overflow-off-by-one-vulnerabilities" source="MISC">http://www.coresecurity.com/content/novell-imanager-buffer-overflow-off-by-one-vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024152" source="SECTRACK">1024152</ref>
      <ref url="http://secunia.com/advisories/40281" source="SECUNIA" adv="1">40281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="imanager">
        <vers num="2.7.0" />
        <vers num="2.7.3" edition="ftf2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1931" published="2010-06-09" name="CVE-2010-1931" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://forums.cubecart.com/index.php?showtopic=41469" source="CONFIRM" patch="1" adv="1">http://forums.cubecart.com/index.php?showtopic=41469</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59245" source="XF">cubecart-shipkey-sql-injection(59245)</ref>
      <ref url="http://www.securityfocus.com/bid/40641" source="BID">40641</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511735/100/0/threaded" source="BUGTRAQ">20100608 [CORE-2010-0415] SQL Injection in CubeCart PHP Free &amp; Commercial Shopping Cart Application</ref>
      <ref url="http://www.coresecurity.com/content/cubecart-php-shopping-cart-sql-injection" source="MISC">http://www.coresecurity.com/content/cubecart-php-shopping-cart-sql-injection</ref>
      <ref url="http://secunia.com/advisories/40102" source="SECUNIA" adv="1">40102</ref>
      <ref url="http://osvdb.org/65250" source="OSVDB">65250</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cubecart" name="cubecart">
        <vers num="4.3.4" />
        <vers num="4.3.5" />
        <vers num="4.3.6" />
        <vers num="4.3.7" />
        <vers num="4.3.8" />
        <vers num="4.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1932" published="2010-06-16" name="CVE-2010-1932" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59421" source="XF">xnview-mbm-bo(59421)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1468" source="VUPEN" adv="1">ADV-2010-1468</ref>
      <ref url="http://www.securitytracker.com/id?1024100" source="SECTRACK">1024100</ref>
      <ref url="http://www.securityfocus.com/bid/40852" source="BID">40852</ref>
      <ref url="http://www.coresecurity.com/content/XnView-MBM-Processing-Heap-Overflow" source="MISC">http://www.coresecurity.com/content/XnView-MBM-Processing-Heap-Overflow</ref>
      <ref url="http://secunia.com/advisories/40141" source="SECUNIA" adv="1">40141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xnview" name="xnview">
        <vers num="1.97.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1934" published="2010-05-12" name="CVE-2010-1934" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) categorie.class.php, (2) profil.class.php, (3) collectivite.class.php, (4) ressource.class.php, (5) droit.class.php, (6) utilisateur.class.php, and (7) planning.class.php in obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/64192" source="OSVDB">64192</ref>
      <ref url="http://www.osvdb.org/64191" source="OSVDB">64191</ref>
      <ref url="http://www.osvdb.org/64189" source="OSVDB">64189</ref>
      <ref url="http://www.osvdb.org/64188" source="OSVDB">64188</ref>
      <ref url="http://www.osvdb.org/64187" source="OSVDB">64187</ref>
      <ref url="http://www.osvdb.org/64186" source="OSVDB">64186</ref>
      <ref url="http://www.exploit-db.com/exploits/12365" source="EXPLOIT-DB">12365</ref>
      <ref url="http://secunia.com/advisories/39606" source="SECUNIA" adv="1">39606</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openplanning-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openplanning-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openplanning">
        <vers num="1.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1935" published="2010-05-12" name="CVE-2010-1935" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58090" source="XF">openpresse-soustab-file-include(58090)</ref>
      <ref url="http://www.osvdb.org/64194" source="OSVDB">64194</ref>
      <ref url="http://www.exploit-db.com/exploits/12364" source="EXPLOIT-DB">12364</ref>
      <ref url="http://secunia.com/advisories/39605" source="SECUNIA" adv="1">39605</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openpresse-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openpresse-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openpresse">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1936" published="2010-05-12" name="CVE-2010-1936" modified="2010-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58129" source="XF">opencominterne-soustab-file-include(58129)</ref>
      <ref url="http://www.osvdb.org/64211" source="OSVDB">64211</ref>
      <ref url="http://www.exploit-db.com/exploits/12396" source="EXPLOIT-DB">12396</ref>
      <ref url="http://secunia.com/advisories/39623" source="SECUNIA" adv="1">39623</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/opencominterne-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/opencominterne-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="opencominterne">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1937" published="2010-06-15" name="CVE-2010-1937" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB before 1.3.8 might allow remote attackers to execute arbitrary code via a Content-Length HTTP header that specifies a value too small for the amount of POST data, aka bug #3001896.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1312" source="VUPEN" adv="1">ADV-2010-1312</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=3001896&amp;group_id=128809&amp;atid=712784" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=3001896&amp;group_id=128809&amp;atid=712784</ref>
      <ref url="http://secunia.com/advisories/40018" source="SECUNIA" adv="1">40018</ref>
      <ref url="http://sblim.cvs.sourceforge.net/viewvc/sblim/sfcb/httpAdapter.c?r1=1.84&amp;r2=1.85" source="CONFIRM">http://sblim.cvs.sourceforge.net/viewvc/sblim/sfcb/httpAdapter.c?r1=1.84&amp;r2=1.85</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127549079109192&amp;w=2" source="MLIST">[oss-security] 20100601 SFCB vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="standards_based_linux_instrumentation" name="sblim-sfcb">
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers prev="1" num="1.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1938" published="2010-05-28" name="CVE-2010-1938" modified="2011-07-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40403" source="BID">40403</ref>
      <ref url="http://www.exploit-db.com/exploits/12762" source="EXPLOIT-DB">12762</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2281" source="DEBIAN">DSA-2281</ref>
      <ref url="http://site.pi3.com.pl/adv/libopie-adv.txt" source="MISC">http://site.pi3.com.pl/adv/libopie-adv.txt</ref>
      <ref url="http://securitytracker.com/id?1025709" source="SECTRACK">1025709</ref>
      <ref url="http://securitytracker.com/id?1024040" source="SECTRACK">1024040</ref>
      <ref url="http://securityreason.com/securityalert/7450" source="SREASON">7450</ref>
      <ref url="http://securityreason.com/achievement_securityalert/87" source="SREASONRES">20100527 libopie __readrec() off-by one (FreeBSD ftpd remote PoC)</ref>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-10:05.opie.asc" source="FREEBSD" adv="1">FreeBSD-SA-10:05</ref>
      <ref url="http://secunia.com/advisories/45136" source="SECUNIA">45136</ref>
      <ref url="http://secunia.com/advisories/39966" source="SECUNIA" adv="1">39966</ref>
      <ref url="http://secunia.com/advisories/39963" source="SECUNIA" adv="1">39963</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584932" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=584932</ref>
      <ref url="http://blog.pi3.com.pl/?p=111" source="MISC">http://blog.pi3.com.pl/?p=111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nrl" name="opie">
        <vers num="2.10" />
        <vers num="2.11" />
        <vers num="2.2" />
        <vers num="2.21" />
        <vers num="2.22" />
        <vers num="2.3" />
        <vers num="2.32" />
        <vers num="2.4" />
        <vers prev="1" num="2.4.1" edition="test1" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6" edition="stable" />
        <vers num="6.4" edition="release" />
        <vers num="6.4" edition="release_p2" />
        <vers num="6.4" edition="release_p3" />
        <vers num="6.4" edition="release_p4" />
        <vers num="6.4" edition="release_p5" />
        <vers num="6.4" edition="stable" />
        <vers num="7.0" edition="beta_4" />
        <vers num="7.0" edition="current" />
        <vers num="7.0" edition="pre-release" />
        <vers num="7.0" edition="release" />
        <vers num="7.0" edition="release-p12" />
        <vers num="7.0" edition="release-p8" />
        <vers num="7.0" edition="release-p9" />
        <vers num="7.0" edition="releng" />
        <vers num="7.0" edition="stable" />
        <vers num="7.0-release" />
        <vers num="7.0_beta4" />
        <vers num="7.0_releng" />
        <vers num="7.1" edition="pre-release" />
        <vers num="7.1" edition="rc1" />
        <vers num="7.1" edition="release-p1" />
        <vers num="7.1" edition="release-p2" />
        <vers num="7.1" edition="release-p4" />
        <vers num="7.1" edition="release-p5" />
        <vers num="7.1" edition="release-p6" />
        <vers num="7.1" edition="stable" />
        <vers num="7.2" edition="pre-release" />
        <vers num="7.2" edition="stable" />
        <vers num="8.0" />
        <vers num="8.1-prerelease" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1939" published="2010-05-13" name="CVE-2010-1939" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.</descript>
      <descript source="nvd">CWE-416 'Use After Free'

http://cwe.mitre.org/data/definitions/416.html</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/943165" source="CERT-VN">VU#943165</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1097" source="VUPEN" patch="1" adv="1">ADV-2010-1097</ref>
      <ref url="http://www.securityfocus.com/bid/39990" source="BID">39990</ref>
      <ref url="http://www.osvdb.org/64482" source="OSVDB">64482</ref>
      <ref url="http://securitytracker.com/id?1023958" source="SECTRACK">1023958</ref>
      <ref url="http://secunia.com/advisories/39670" source="SECUNIA" adv="1">39670</ref>
      <ref url="http://reviews.cnet.com/8301-13727_7-20004709-263.html" source="MISC">http://reviews.cnet.com/8301-13727_7-20004709-263.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6748" source="OVAL">oval:org.mitre.oval:def:6748</ref>
      <ref url="http://h07.w.interia.pl/Safari.rar" source="MISC">http://h07.w.interia.pl/Safari.rar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1940" published="2010-05-14" name="CVE-2010-1940" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58620" source="XF">safari-http-request-information-disclosure(58620)</ref>
      <ref url="http://secunia.com/advisories/39670" source="SECUNIA" adv="1">39670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1941" published="2010-05-19" name="CVE-2010-1941" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in NEC WebSAM DeploymentManager 5.13 and earlier, as used in SigmaSystemCenter 2.1 Update2 and earlier, BladeSystemCenter, ExpressSystemCenter, and VirtualPCCenter 2.2 and earlier, allows remote attackers to cause a denial of service (OS shutdown or restart) via unknown vectors related to Client Service for DPM and crafted packets to port 56010.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40196" source="BID">40196</ref>
      <ref url="http://www.nec.co.jp/security-info/secinfo/nv10-004.html" source="CONFIRM" adv="1">http://www.nec.co.jp/security-info/secinfo/nv10-004.html</ref>
      <ref url="http://secunia.com/advisories/39802" source="SECUNIA" adv="1">39802</ref>
      <ref url="http://osvdb.org/64700" source="OSVDB">64700</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000019.html" source="JVNDB">JVNDB-2010-000019</ref>
      <ref url="http://jvn.jp/en/jp/JVN90872372/index.html" source="JVN">JVN#90872372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nec" name="bladesystemcenter">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="nec" name="expresssystemcenter">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="nec" name="sigmasystemcenter">
        <vers prev="1" num="2.1" edition="2" />
      </prod>
      <prod vendor="nec" name="virtualpccenter">
        <vers prev="1" num="2.2" />
      </prod>
      <prod vendor="nec" name="websam_deploymentmanager">
        <vers prev="1" num="5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1942" published="2010-05-19" name="CVE-2010-1942" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Servlet service in Fujitsu Limited Interstage Application Server 3.0 through 7.0, as used in Interstage Application Framework Suite, Interstage Business Application Server, and Interstage List Manager, allows attackers to obtain sensitive information or force invalid requests to be processed via unknown vectors related to unspecified invalid requests and settings on the load balancing device.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1165" source="VUPEN" patch="1" adv="1">ADV-2010-1165</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/interstage-201001e.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/support/software/security/products-f/interstage-201001e.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58634" source="XF">interstage-servlet-information-disclosure(58634)</ref>
      <ref url="http://www.securityfocus.com/bid/40189" source="BID">40189</ref>
      <ref url="http://software.fujitsu.com/jp/security/vulnerabilities/jvn-90248889.html" source="CONFIRM" adv="1">http://software.fujitsu.com/jp/security/vulnerabilities/jvn-90248889.html</ref>
      <ref url="http://secunia.com/advisories/39803" source="SECUNIA" adv="1">39803</ref>
      <ref url="http://osvdb.org/64703" source="OSVDB">64703</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000018.html" source="JVNDB">JVNDB-2010-000018</ref>
      <ref url="http://jvn.jp/en/jp/JVN90248889/index.html" source="JVN">JVN#90248889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="interstage_application_server">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":standard" />
        <vers num="3.0" edition=":enterprise" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":web_j" />
        <vers num="4.0" edition=":standard" />
        <vers num="4.0" edition=":enterprise" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":standard" />
        <vers num="4.1" edition=":web_j" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":enterprise" />
        <vers num="5.0" edition=":standard" />
        <vers num="5.0" edition=":web_j" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":enterprise" />
        <vers num="5.0.1" edition=":plus_developer" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":enterprise" />
        <vers num="6.0" edition=":plus" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":plus" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":enterprise" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":enterprise" />
        <vers num="7.0.1" edition=":plus" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1943" published="2010-05-19" name="CVE-2010-1943" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in NEC CapsSuite Small Edition PatchMeister 2.0 Update2 and earlier allows remote attackers to cause a denial of service (OS shutdown or restart) via vectors related to Client Service for PTM and crafted packets to port 56015.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1166" source="VUPEN" adv="1">ADV-2010-1166</ref>
      <ref url="http://www.securityfocus.com/bid/40190" source="BID">40190</ref>
      <ref url="http://www.nec.co.jp/security-info/secinfo/nv10-005.html" source="CONFIRM" adv="1">http://www.nec.co.jp/security-info/secinfo/nv10-005.html</ref>
      <ref url="http://www.ipa.go.jp/about/press/20100517_2.html" source="MISC">http://www.ipa.go.jp/about/press/20100517_2.html</ref>
      <ref url="http://secunia.com/advisories/39800" source="SECUNIA" adv="1">39800</ref>
      <ref url="http://osvdb.org/64701" source="OSVDB">64701</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000020.html" source="JVNDB">JVNDB-2010-000020</ref>
      <ref url="http://jvn.jp/en/jp/JVN82749282/index.html" source="JVN">JVN#82749282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nec" name="capsuite_patchmeister">
        <vers num="2.0" edition="2" />
        <vers num="2.0" edition="2:small" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1944" published="2010-05-19" name="CVE-2010-1944" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2) courrierautorisation.class.php, (3) droit.class.php, (4) profil.class.php, (5) temp_defunt_sansemplacement.class.php, (6) utils.class.php, (7) cimetiere.class.php, (8) defunt.class.php, (9) emplacement.class.php, (10) tab_emplacement.class.php, (11) temp_emplacement.class.php, (12) voie.class.php, (13) collectivite.class.php, (14) defunttransfert.class.php, (15) entreprise.class.php, (16) temp_autorisation.class.php, (17) travaux.class.php, (18) zone.class.php, (19) courrier.class.php, (20) dossier.class.php, (21) plans.class.php, (22) temp_defunt.class.php, and (23) utilisateur.class.php in obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58267" source="XF">opencimetiere-pathom-file-include(58267)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1050" source="VUPEN" adv="1">ADV-2010-1050</ref>
      <ref url="http://www.securityfocus.com/bid/39883" source="BID">39883</ref>
      <ref url="http://www.osvdb.org/64245" source="OSVDB">64245</ref>
      <ref url="http://www.osvdb.org/64244" source="OSVDB">64244</ref>
      <ref url="http://www.osvdb.org/64243" source="OSVDB">64243</ref>
      <ref url="http://www.osvdb.org/64242" source="OSVDB">64242</ref>
      <ref url="http://www.osvdb.org/64241" source="OSVDB">64241</ref>
      <ref url="http://www.osvdb.org/64240" source="OSVDB">64240</ref>
      <ref url="http://www.osvdb.org/64239" source="OSVDB">64239</ref>
      <ref url="http://www.osvdb.org/64238" source="OSVDB">64238</ref>
      <ref url="http://www.osvdb.org/64237" source="OSVDB">64237</ref>
      <ref url="http://www.osvdb.org/64236" source="OSVDB">64236</ref>
      <ref url="http://www.osvdb.org/64235" source="OSVDB">64235</ref>
      <ref url="http://www.osvdb.org/64234" source="OSVDB">64234</ref>
      <ref url="http://www.osvdb.org/64233" source="OSVDB">64233</ref>
      <ref url="http://www.osvdb.org/64232" source="OSVDB">64232</ref>
      <ref url="http://www.osvdb.org/64231" source="OSVDB">64231</ref>
      <ref url="http://www.osvdb.org/64230" source="OSVDB">64230</ref>
      <ref url="http://www.osvdb.org/64229" source="OSVDB">64229</ref>
      <ref url="http://www.osvdb.org/64228" source="OSVDB">64228</ref>
      <ref url="http://www.osvdb.org/64227" source="OSVDB">64227</ref>
      <ref url="http://www.osvdb.org/64226" source="OSVDB">64226</ref>
      <ref url="http://www.osvdb.org/64225" source="OSVDB">64225</ref>
      <ref url="http://www.osvdb.org/64224" source="OSVDB">64224</ref>
      <ref url="http://www.osvdb.org/64223" source="OSVDB">64223</ref>
      <ref url="http://www.exploit-db.com/exploits/12476" source="EXPLOIT-DB">12476</ref>
      <ref url="http://secunia.com/advisories/39687" source="SECUNIA" adv="1">39687</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/opencimetiere-rfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/opencimetiere-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="opencimetiere">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1945" published="2010-05-19" name="CVE-2010-1945" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) action.class.php, (2) architecte.class.php, (3) avis.class.php, (4) bible.class.php, and (5) blocnote.class.php in obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/64200" source="OSVDB">64200</ref>
      <ref url="http://www.osvdb.org/64199" source="OSVDB">64199</ref>
      <ref url="http://www.osvdb.org/64198" source="OSVDB">64198</ref>
      <ref url="http://www.osvdb.org/64197" source="OSVDB">64197</ref>
      <ref url="http://www.osvdb.org/64196" source="OSVDB">64196</ref>
      <ref url="http://www.exploit-db.com/exploits/12366" source="EXPLOIT-DB">12366</ref>
      <ref url="http://secunia.com/advisories/39607" source="SECUNIA" adv="1">39607</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openfoncier-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openfoncier-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openfoncier">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1946" published="2010-05-19" name="CVE-2010-1946" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation_normale.class.php, (2) collectivite.class.php, (3) dossier.class.php, (4) norme_simplifiee.class.php, (5) registre.class.php, (6) autorisation_unique.class.php, (7) demande_avis.class.php, (8) droit.class.php, (9) organisme.class.php, (10) service.class.php, (11) categorie_donnee.class.php, (12) destinataire.class.php, (13) profil.class.php, (14) tabdyn_visu.class.php, (15) categorie_personne.class.php, (16) dispense.class.php, (17) modificatif.class.php, (18) reference.class.php, and (19) utilisateur.class.php in obj/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39611" source="BID">39611</ref>
      <ref url="http://www.osvdb.org/63963" source="OSVDB">63963</ref>
      <ref url="http://www.osvdb.org/63962" source="OSVDB">63962</ref>
      <ref url="http://www.osvdb.org/63961" source="OSVDB">63961</ref>
      <ref url="http://www.osvdb.org/63960" source="OSVDB">63960</ref>
      <ref url="http://www.osvdb.org/63959" source="OSVDB">63959</ref>
      <ref url="http://www.osvdb.org/63958" source="OSVDB">63958</ref>
      <ref url="http://www.osvdb.org/63957" source="OSVDB">63957</ref>
      <ref url="http://www.osvdb.org/63956" source="OSVDB">63956</ref>
      <ref url="http://www.osvdb.org/63955" source="OSVDB">63955</ref>
      <ref url="http://www.osvdb.org/63954" source="OSVDB">63954</ref>
      <ref url="http://www.osvdb.org/63953" source="OSVDB">63953</ref>
      <ref url="http://www.osvdb.org/63952" source="OSVDB">63952</ref>
      <ref url="http://www.osvdb.org/63951" source="OSVDB">63951</ref>
      <ref url="http://www.osvdb.org/63950" source="OSVDB">63950</ref>
      <ref url="http://www.osvdb.org/63949" source="OSVDB">63949</ref>
      <ref url="http://www.osvdb.org/63948" source="OSVDB">63948</ref>
      <ref url="http://www.osvdb.org/63947" source="OSVDB">63947</ref>
      <ref url="http://www.osvdb.org/63946" source="OSVDB">63946</ref>
      <ref url="http://www.osvdb.org/63945" source="OSVDB">63945</ref>
      <ref url="http://www.exploit-db.com/exploits/12313" source="EXPLOIT-DB">12313</ref>
      <ref url="http://secunia.com/advisories/39534" source="SECUNIA" adv="1">39534</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openregistrecil-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openregistrecil-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openregistrecil">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1947" published="2010-05-19" name="CVE-2010-1947" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter.  NOTE: this may be related to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39611" source="BID">39611</ref>
      <ref url="http://www.osvdb.org/63964" source="OSVDB">63964</ref>
      <ref url="http://www.exploit-db.com/exploits/12313" source="EXPLOIT-DB">12313</ref>
      <ref url="http://secunia.com/advisories/39534" source="SECUNIA" adv="1">39534</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openregistrecil-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openregistrecil-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openregistrecil">
        <vers num="1.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1948" published="2010-05-19" name="CVE-2010-1948" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/64195" source="OSVDB">64195</ref>
      <ref url="http://www.exploit-db.com/exploits/12366" source="EXPLOIT-DB">12366</ref>
      <ref url="http://secunia.com/advisories/39607" source="SECUNIA" adv="1">39607</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/openfoncier-rfilfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/openfoncier-rfilfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="openfoncier">
        <vers num="2.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1949" published="2010-05-19" name="CVE-2010-1949" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/12305" source="EXPLOIT-DB">12305</ref>
      <ref url="http://secunia.com/advisories/39536" source="SECUNIA" adv="1">39536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emultisoft" name="com_jnewspaper">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1950" published="2010-05-19" name="CVE-2010-1950" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39536" source="SECUNIA" adv="1">39536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emultisoft" name="com_jnewspaper">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1951" published="2010-05-19" name="CVE-2010-1951" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the DOCUMENT_ROOT parameter to (1) news.php, (2) submitComment.php, and (3) sqlConnect.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57873" source="XF">60cyclecms-documentroot-file-include(57873)</ref>
      <ref url="http://www.securityfocus.com/bid/39473" source="BID">39473</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/510721/100/0/threaded" source="BUGTRAQ">20100414 60cycleCMS (DOCUMENT_ROOT) Multiple Local File Inclusion Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/12249" source="EXPLOIT-DB">12249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="60cycle" name="60cyclecms">
        <vers num="2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1952" published="2010-05-19" name="CVE-2010-1952" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57845" source="XF">combeeheard-index-file-inlclude(57845)</ref>
      <ref url="http://www.securityfocus.com/bid/39506" source="BID">39506</ref>
      <ref url="http://www.exploit-db.com/exploits/12239" source="EXPLOIT-DB">12239</ref>
      <ref url="http://secunia.com/advisories/39475" source="SECUNIA" adv="1">39475</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlabeeheardlite-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlabeeheardlite-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmstactics" name="com_beeheard">
        <vers num="1.0" />
      </prod>
      <prod vendor="cmstactics" name="com_beeheardlite">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1953" published="2010-05-19" name="CVE-2010-1953" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0927" source="VUPEN" adv="1">ADV-2010-0927</ref>
      <ref url="http://www.securityfocus.com/bid/39551" source="BID">39551</ref>
      <ref url="http://www.exploit-db.com/exploits/12288" source="EXPLOIT-DB">12288</ref>
      <ref url="http://secunia.com/advisories/39530" source="SECUNIA" adv="1">39530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlacomponent.inetlanka" name="com_multimap">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1954" published="2010-05-19" name="CVE-2010-1954" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the iNetLanka Multiple root (com_multiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/0928" source="VUPEN" adv="1">ADV-2010-0928</ref>
      <ref url="http://www.securityfocus.com/bid/39552" source="BID">39552</ref>
      <ref url="http://www.exploit-db.com/exploits/12287" source="EXPLOIT-DB">12287</ref>
      <ref url="http://secunia.com/advisories/39531" source="SECUNIA" adv="1">39531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlacomponent.inetlanka" name="com_multiroot">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1955" published="2010-05-19" name="CVE-2010-1955" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57846" source="XF">comblogfactory-index-file-inlclude(57846)</ref>
      <ref url="http://www.securityfocus.com/bid/39508" source="BID">39508</ref>
      <ref url="http://www.exploit-db.com/exploits/12238" source="EXPLOIT-DB">12238</ref>
      <ref url="http://secunia.com/advisories/39473" source="SECUNIA" adv="1">39473</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomladeluxeblog-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomladeluxeblog-lfi.txt</ref>
      <ref url="http://osvdb.org/63801" source="OSVDB">63801</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thefactory" name="com_blogfactory">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1956" published="2010-05-19" name="CVE-2010-1956" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.thefactory.ro/all-thefactory-products/gadget-factory-for-joomla-1.5.x/detailed-product-flyer.html" source="CONFIRM" patch="1">http://www.thefactory.ro/all-thefactory-products/gadget-factory-for-joomla-1.5.x/detailed-product-flyer.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57895" source="XF">comgadgetfactory-controller-file-include(57895)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0930" source="VUPEN" adv="1">ADV-2010-0930</ref>
      <ref url="http://www.securityfocus.com/bid/39547" source="BID">39547</ref>
      <ref url="http://www.exploit-db.com/exploits/12285" source="EXPLOIT-DB">12285</ref>
      <ref url="http://secunia.com/advisories/39522" source="SECUNIA" adv="1">39522</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlagadgetfactory-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlagadgetfactory-lfi.txt</ref>
      <ref url="http://osvdb.org/63917" source="OSVDB">63917</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thefactory" name="com_gadgetfactory">
        <vers num="1.0.0" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1957" published="2010-05-19" name="CVE-2010-1957" modified="2010-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57849" source="XF">comlovefactory-index-file-inlclude(57849)</ref>
      <ref url="http://www.securityfocus.com/bid/39512" source="BID">39512</ref>
      <ref url="http://www.exploit-db.com/exploits/12235" source="EXPLOIT-DB">12235</ref>
      <ref url="http://secunia.com/advisories/39471" source="SECUNIA" adv="1">39471</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlalovefactory-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlalovefactory-lfi.txt</ref>
      <ref url="http://osvdb.org/63803" source="OSVDB">63803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thefactory" name="com_lovefactory">
        <vers num="1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1958" published="2010-06-21" name="CVE-2010-1958" modified="2010-06-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40923" source="BID" patch="1">40923</ref>
      <ref url="http://drupal.org/node/829808" source="CONFIRM" patch="1">http://drupal.org/node/829808</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59500" source="XF">filefieldmodule-filepath-xss(59500)</ref>
      <ref url="http://www.madirish.net/?article=461" source="MISC">http://www.madirish.net/?article=461</ref>
      <ref url="http://secunia.com/advisories/40186" source="SECUNIA" adv="1">40186</ref>
      <ref url="http://osvdb.org/65611" source="OSVDB">65611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quicksketch" name="filefield">
        <vers num="5.x-1.x-dev" />
        <vers num="5.x-2.0" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.2" />
        <vers num="5.x-2.3" edition="rc2" />
        <vers num="5.x-2.3" edition="rc3" />
        <vers num="5.x-2.3" edition="rc4" />
        <vers num="5.x-2.4" />
        <vers num="5.x-2.x-dev" />
        <vers num="6.x-1.0" edition="alpha1" />
        <vers num="6.x-1.0" edition="alpha2" />
        <vers num="6.x-1.0" edition="alpha3" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-3.0" edition="alpha1" />
        <vers num="6.x-3.0" edition="alpha2" />
        <vers num="6.x-3.0" edition="alpha3" />
        <vers num="6.x-3.0" edition="alpha4" />
        <vers num="6.x-3.0" edition="alpha5" />
        <vers num="6.x-3.0" edition="alpha6" />
        <vers num="6.x-3.0" edition="alpha7" />
        <vers num="6.x-3.0" edition="beta1" />
        <vers num="6.x-3.0" edition="beta2" />
        <vers num="6.x-3.0" edition="beta3" />
        <vers num="6.x-3.0" edition="rc1" />
        <vers num="6.x-3.1" />
        <vers num="6.x-3.2" />
        <vers num="6.x-3.3" />
        <vers num="6.x-3.5" />
        <vers num="6.x-3.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1959" published="2010-05-27" name="CVE-2010-1959" modified="2010-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40371" source="BID">40371</ref>
      <ref url="http://securitytracker.com/id?1024025" source="SECTRACK">1024025</ref>
      <ref url="http://secunia.com/advisories/39943" source="SECUNIA" adv="1">39943</ref>
      <ref url="http://osvdb.org/64917" source="OSVDB">64917</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01373684" source="HP" adv="1">SSRT071487</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01373684" source="HP" adv="1">SSRT071487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="mercury_testdirector_for_quality_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1960" published="2010-06-09" name="CVE-2010-1960" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long, invalid option to jovgraph.exe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127602909915281&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02537</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127602909915281&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02537</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59249" source="XF">ovnnm-ovwebsnmpsrv-bo(59249)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-105/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-105/</ref>
      <ref url="http://www.securitytracker.com/id?1024071" source="SECTRACK">1024071</ref>
      <ref url="http://www.securityfocus.com/bid/40637" source="BID">40637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511734/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-105: Hewlett-Packard OpenView NNM ovwebsnmpsrv.exe Bad Option Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/40101" source="SECUNIA" adv="1">40101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1961" published="2010-06-09" name="CVE-2010-1961" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127602909915281&amp;w=2" source="HP" patch="1" adv="1">SSRT010027</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127602909915281&amp;w=2" source="HP" patch="1" adv="1">SSRT010027</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59250" source="XF">ovnnm-getproxiedstorageaddress-bo(59250)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-106/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-106/</ref>
      <ref url="http://www.securitytracker.com/id?1024071" source="SECTRACK">1024071</ref>
      <ref url="http://www.securityfocus.com/bid/40638" source="BID">40638</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511731/100/0/threaded" source="BUGTRAQ">20100608 ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/40101" source="SECUNIA" adv="1">40101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1962" published="2010-06-07" name="CVE-2010-1962" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127557820805729&amp;w=2" source="HP" patch="1" adv="1">HPSBST02536</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59099" source="XF">hp-storageworks-mirroring-unauth-access(59099)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1319" source="VUPEN">ADV-2010-1319</ref>
      <ref url="http://www.securitytracker.com/id?1024054" source="SECTRACK">1024054</ref>
      <ref url="http://www.securityfocus.com/bid/40539" source="BID">40539</ref>
      <ref url="http://secunia.com/advisories/40044" source="SECUNIA">40044</ref>
      <ref url="http://osvdb.org/65142" source="OSVDB">65142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storageworks_storage_mirroring">
        <vers num="5" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1963" published="2010-06-07" name="CVE-2010-1963" modified="2010-06-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127557884206863&amp;w=2" source="HP" patch="1" adv="1">HPSBMA02538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="servicecenter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1964" published="2010-06-17" name="CVE-2010-1964" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seclists.org/bugtraq/2010/Jun/152" source="HP" patch="1">SSRT010027</ref>
      <ref url="http://seclists.org/bugtraq/2010/Jun/152" source="HP" patch="1">SSRT010027</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-108" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-108</ref>
      <ref url="http://www.securityfocus.com/bid/40873" source="BID">40873</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511854/100/0/threaded" source="BUGTRAQ">20100616 ZDI-10-108: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/8155" source="SREASON">8155</ref>
      <ref url="http://osvdb.org/65552" source="OSVDB">65552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:hp-ux" />
        <vers num="7.53" edition="-:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1965" published="2010-07-15" name="CVE-2010-1965" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Insight Orchestration for Windows before 6.1 allows remote attackers to read or modify data via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1794" source="VUPEN" adv="1">ADV-2010-1794</ref>
      <ref url="http://securitytracker.com/id?1024183" source="SECTRACK">1024183</ref>
      <ref url="http://secunia.com/advisories/40549" source="SECUNIA" adv="1">40549</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02280158" source="HP">HPSBMA02548</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02280158" source="HP">HPSBMA02548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_orchestration">
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1966" published="2010-07-15" name="CVE-2010-1966" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Insight Control power management for Windows before 6.1 allows local users to read or modify data, or cause a denial of service, via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1795" source="VUPEN" adv="1">ADV-2010-1795</ref>
      <ref url="http://securitytracker.com/id?1024184" source="SECTRACK">1024184</ref>
      <ref url="http://secunia.com/advisories/40550" source="SECUNIA" adv="1">40550</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282361" source="HP">HPSBMA02549</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282361" source="HP">HPSBMA02549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_control">
        <vers num="3.00" />
        <vers num="3.10" />
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1967" published="2010-07-15" name="CVE-2010-1967" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN" adv="1">ADV-2010-1792</ref>
      <ref url="http://securitytracker.com/id?1024185" source="SECTRACK">1024185</ref>
      <ref url="http://secunia.com/advisories/40544" source="SECUNIA" adv="1">40544</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282377" source="HP">HPSBMA02550</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282377" source="HP">HPSBMA02550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_software_installer">
        <vers num="3.00" />
        <vers num="3.10" />
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1968" published="2010-07-15" name="CVE-2010-1968" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN" adv="1">ADV-2010-1792</ref>
      <ref url="http://securitytracker.com/id?1024185" source="SECTRACK">1024185</ref>
      <ref url="http://secunia.com/advisories/40544" source="SECUNIA" adv="1">40544</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282377" source="HP">HPSBMA02550</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282377" source="HP">HPSBMA02550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_software_installer">
        <vers num="3.00" />
        <vers num="3.10" />
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1969" published="2010-07-22" name="CVE-2010-1969" modified="2010-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Virtual Connect Enterprise Manager for Windows before 6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02283465&amp;admit=109447626+1279054975923+28353475" source="HP">SSRT100165</ref>
      <ref url="http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02283465&amp;admit=109447626+1279054975923+28353475" source="HP">SSRT100165</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1797" source="VUPEN" adv="1">ADV-2010-1797</ref>
      <ref url="http://www.securitytracker.com/id?1024181" source="SECTRACK">1024181</ref>
      <ref url="http://secunia.com/advisories/40552" source="SECUNIA" adv="1">40552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtual_connect_enterprise_manager">
        <vers num="6.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1970" published="2010-07-15" name="CVE-2010-1970" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN" adv="1">ADV-2010-1792</ref>
      <ref url="http://securitytracker.com/id?1024186" source="SECTRACK">1024186</ref>
      <ref url="http://secunia.com/advisories/40553" source="SECUNIA" adv="1">40553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_software_installer">
        <vers num="3.00" />
        <vers num="3.10" />
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1971" published="2010-07-15" name="CVE-2010-1971" modified="2010-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN" adv="1">ADV-2010-1792</ref>
      <ref url="http://securitytracker.com/id?1024186" source="SECTRACK">1024186</ref>
      <ref url="http://secunia.com/advisories/40553" source="SECUNIA" adv="1">40553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="insight_software_installer">
        <vers num="3.00" />
        <vers num="3.10" />
        <vers prev="1" num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1972" published="2010-07-22" name="CVE-2010-1972" modified="2010-07-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:P/A:P)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The default configuration of HP Client Automation (HPCA) Enterprise Infrastructure (aka Radia) allows remote attackers to read log files, and consequently cause a denial of service or have unspecified other impact, via web requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1024191" source="SECTRACK">1024191</ref>
      <ref url="http://secunia.com/advisories/40592" source="SECUNIA" adv="1">40592</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127905601332098&amp;w=2" source="HP" adv="1">HPSBMA02555</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127905601332098&amp;w=2" source="HP" adv="1">HPSBMA02555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="client_automation_enterprise_infrastructure">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1973" published="2010-07-22" name="CVE-2010-1973" modified="2010-07-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and earlier on the Itanium platform, allows local users to gain privileges or obtain sensitive information via unknown vectors.</descript>
      <descript source="nvd">Per: http://marc.info/?l=bugtraq&amp;m=127905660900687&amp;w=2

'impacted versions are listed.
HP OpenVMS ALPHA v 8.3, v 8.2, v 7.3-2 and earlier
HP OpenVMS Itanium v 8.3-1H1, v 8.3, v 8.2-1 and earlier'</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://marc.info/?l=bugtraq&amp;m=127905660900687&amp;w=2

'HP has made the following patch kits available to resolve the vulnerability.
Patch kit information and installation instructions are provided with each kit as noted below . The patch kits and installation instructions are available from the following location using anonymous ftp:

ftp://ftp.itrc.hp.com/openvms_patches
</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127905660900687&amp;w=2" source="HP" patch="1" adv="1">HPSBOV02539</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127905660900687&amp;w=2" source="HP" patch="1" adv="1">HPSBOV02539</ref>
      <ref url="http://securitytracker.com/id?1024190" source="SECTRACK">1024190</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openvms">
        <vers num="6.2" />
        <vers num="7.2" />
        <vers num="7.2-1" />
        <vers num="7.2-1h1" />
        <vers num="7.2-2" />
        <vers num="7.2-6c2" />
        <vers num="7.3" />
        <vers num="7.3-1" />
        <vers prev="1" num="7.3-2" />
        <vers num="8.2" />
        <vers prev="1" num="8.2-1" />
        <vers num="8.3" />
        <vers num="8.3-1h1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-1974" reject="1" published="2010-05-19" name="CVE-2010-1974" modified="2010-06-23">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1168.  Reason: This candidate is a duplicate of CVE-2010-1168.  Notes: All CVE users should reference CVE-2010-1168 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1975" published="2010-05-19" name="CVE-2010-1975" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1221" source="VUPEN">ADV-2010-1221</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1207" source="VUPEN">ADV-2010-1207</ref>
      <ref url="http://www.securityfocus.com/bid/40304" source="BID">40304</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-4-4.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-4-4.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-3-11.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-3-11.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-2-17.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-2-17.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-1-21.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-1-21.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-8-0-25.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-8-0-25.html</ref>
      <ref url="http://www.postgresql.org/docs/current/static/release-7-4-29.html" source="CONFIRM">http://www.postgresql.org/docs/current/static/release-7-4-29.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:103" source="MANDRIVA">MDVSA-2010:103</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2051" source="DEBIAN">DSA-2051</ref>
      <ref url="http://secunia.com/advisories/39939" source="SECUNIA">39939</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11004" source="OVAL">oval:org.mitre.oval:def:11004</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.10" />
        <vers num="7.4.11" />
        <vers num="7.4.12" />
        <vers num="7.4.13" />
        <vers num="7.4.14" />
        <vers num="7.4.15" />
        <vers num="7.4.16" />
        <vers num="7.4.17" />
        <vers num="7.4.18" />
        <vers num="7.4.19" />
        <vers num="7.4.2" />
        <vers num="7.4.20" />
        <vers num="7.4.21" />
        <vers num="7.4.22" />
        <vers num="7.4.23" />
        <vers num="7.4.24" />
        <vers num="7.4.25" />
        <vers num="7.4.26" />
        <vers num="7.4.27" />
        <vers num="7.4.28" />
        <vers num="7.4.3" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.4.6" />
        <vers num="7.4.7" />
        <vers num="7.4.8" />
        <vers num="7.4.9" />
        <vers num="8.0" />
        <vers num="8.0.0" />
        <vers num="8.0.1" />
        <vers num="8.0.10" />
        <vers num="8.0.11" />
        <vers num="8.0.12" />
        <vers num="8.0.13" />
        <vers num="8.0.14" />
        <vers num="8.0.15" />
        <vers num="8.0.16" />
        <vers num="8.0.17" />
        <vers num="8.0.18" />
        <vers num="8.0.19" />
        <vers num="8.0.2" />
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.0.23" />
        <vers num="8.0.24" />
        <vers num="8.0.3" />
        <vers num="8.0.4" />
        <vers num="8.0.5" />
        <vers num="8.0.6" />
        <vers num="8.0.7" />
        <vers num="8.0.8" />
        <vers num="8.0.9" />
        <vers num="8.1" />
        <vers num="8.1.0" />
        <vers num="8.1.1" />
        <vers num="8.1.10" />
        <vers num="8.1.11" />
        <vers num="8.1.12" />
        <vers num="8.1.13" />
        <vers num="8.1.14" />
        <vers num="8.1.15" />
        <vers num="8.1.16" />
        <vers num="8.1.17" />
        <vers num="8.1.18" />
        <vers num="8.1.19" />
        <vers num="8.1.2" />
        <vers num="8.1.20" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.1.8" />
        <vers num="8.1.9" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.10" />
        <vers num="8.2.11" />
        <vers num="8.2.12" />
        <vers num="8.2.13" />
        <vers num="8.2.14" />
        <vers num="8.2.15" />
        <vers num="8.2.16" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.2.8" />
        <vers num="8.2.9" />
        <vers num="8.3" />
        <vers num="8.3.1" />
        <vers num="8.3.10" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.3.7" />
        <vers num="8.3.8" />
        <vers num="8.3.9" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.2" />
        <vers num="8.4.3" />
        <vers num="9.0.0" edition="beta1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1976" published="2010-05-19" name="CVE-2010-1976" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/758456" source="CONFIRM" patch="1">http://drupal.org/node/758456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57446" source="XF">taxonomy-breadcrumb-name-xss(57446)</ref>
      <ref url="http://secunia.com/advisories/39138" source="SECUNIA" adv="1">39138</ref>
      <ref url="http://osvdb.org/63424" source="OSVDB">63424</ref>
      <ref url="http://drupal.org/node/757980" source="MISC">http://drupal.org/node/757980</ref>
      <ref url="http://drupal.org/node/757974" source="MISC" adv="1">http://drupal.org/node/757974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_nichols" name="taxonomy_breadcrumb">
        <vers num="6.x-0.1" edition="beta" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1977" published="2010-05-19" name="CVE-2010-1977" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the J!WHMCS Integrator (com_jwhmcs) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39243" source="BID">39243</ref>
      <ref url="http://www.exploit-db.com/exploits/12083" source="EXPLOIT-DB">12083</ref>
      <ref url="http://secunia.com/advisories/39356" source="SECUNIA" adv="1">39356</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gohigheris" name="com_jwhmcs">
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1978" published="2010-05-19" name="CVE-2010-1978" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in default_theme.php in FreePHPBlogSoftware 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpincdir parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57560" source="XF">fpbs-phpincdir-file-include(57560)</ref>
      <ref url="http://www.securityfocus.com/bid/39233" source="BID">39233</ref>
      <ref url="http://www.osvdb.org/63558" source="OSVDB">63558</ref>
      <ref url="http://www.exploit-db.com/exploits/12063" source="EXPLOIT-DB">12063</ref>
      <ref url="http://secunia.com/advisories/39321" source="SECUNIA" adv="1">39321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freephpblogsoftware" name="freephpblogsoftware">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1979" published="2010-05-19" name="CVE-2010-1979" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57570" source="XF">comdatafeeds-index-file-include(57570)</ref>
      <ref url="http://www.securityfocus.com/bid/39246" source="BID">39246</ref>
      <ref url="http://www.exploit-db.com/exploits/12088" source="EXPLOIT-DB">12088</ref>
      <ref url="http://secunia.com/advisories/39360" source="SECUNIA" adv="1">39360</ref>
    </refs>
    <vuln_soft>
      <prod vendor="affiliatefeeds" name="com_datafeeds">
        <vers num="build_880" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1980" published="2010-05-19" name="CVE-2010-1980" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39251" source="BID" patch="1">39251</ref>
      <ref url="http://bitbucket.org/roberto.aloi/joomla-flickr/changeset/64ebf6b25030" source="CONFIRM" patch="1">http://bitbucket.org/roberto.aloi/joomla-flickr/changeset/64ebf6b25030</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57573" source="XF">comjoomlaflickr-index-file-include(57573)</ref>
      <ref url="http://www.exploit-db.com/exploits/12085" source="EXPLOIT-DB">12085</ref>
      <ref url="http://secunia.com/advisories/39358" source="SECUNIA" adv="1">39358</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaflickr-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaflickr-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roberto_aloi" name="com_joomlaflickr">
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1981" published="2010-05-19" name="CVE-2010-1981" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57571" source="XF">comfabrik-index-file-include(57571)</ref>
      <ref url="http://www.exploit-db.com/exploits/12087" source="EXPLOIT-DB">12087</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlafabrik-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlafabrik-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fabrikar" name="com_fabrikar">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1982" published="2010-05-19" name="CVE-2010-1982" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/39343" source="BID">39343</ref>
      <ref url="http://www.exploit-db.com/exploits/12121" source="EXPLOIT-DB">12121</ref>
      <ref url="http://secunia.com/advisories/39202" source="SECUNIA" adv="1">39202</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlajavoice-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlajavoice-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomlart" name="com_javoice">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1983" published="2010-05-19" name="CVE-2010-1983" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57511" source="XF">redtwitter-view-file-include(57511)</ref>
      <ref url="http://www.securityfocus.com/bid/39211" source="BID">39211</ref>
      <ref url="http://www.exploit-db.com/exploits/12055" source="EXPLOIT-DB">12055</ref>
      <ref url="http://secunia.com/advisories/39342" source="SECUNIA" adv="1">39342</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/joomlaredtwitter-lfi.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/joomlaredtwitter-lfi.txt</ref>
      <ref url="http://osvdb.org/63533" source="OSVDB">63533</ref>
      <ref url="http://evilc0de.blogspot.com/2010/04/joomla-component-redtwitter-lfi-vuln.html" source="MISC">http://evilc0de.blogspot.com/2010/04/joomla-component-redtwitter-lfi-vuln.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redcomponent" name="com_redtwitter">
        <vers num="1.0b10" />
        <vers num="1.0b11" />
        <vers num="1.0b8" />
        <vers num="1.0b9" />
        <vers num="1.0b9.1" />
        <vers num="1.0b94.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1984" published="2010-05-19" name="CVE-2010-1984" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonomy term name in a Breadcrumb display.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/758456" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/758456</ref>
      <ref url="http://drupal.org/node/757980" source="MISC" patch="1">http://drupal.org/node/757980</ref>
      <ref url="http://drupal.org/node/757974" source="MISC" patch="1">http://drupal.org/node/757974</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/57446" source="XF">taxonomy-breadcrumb-name-xss(57446)</ref>
      <ref url="http://secunia.com/advisories/39138" source="SECUNIA" adv="1">39138</ref>
      <ref url="http://osvdb.org/63424" source="OSVDB">63424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="michael_nichols" name="taxonomy_breadcrumb">
        <vers num="5.x-1.0" edition="dev" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="6.x-0.1" edition="beta" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1985" published="2010-05-19" name="CVE-2010-1985" modified="2010-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in Six Apart Movable Type 5.0 and 5.01 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1136" source="VUPEN" adv="1">ADV-2010-1136</ref>
      <ref url="http://www.movabletype.org/documentation/appendices/release-notes/movable-type-502.html" source="CONFIRM">http://www.movabletype.org/documentation/appendices/release-notes/movable-type-502.html</ref>
      <ref url="http://www.movabletype.com/blog/2010/05/movable-type-502.html" source="CONFIRM">http://www.movabletype.com/blog/2010/05/movable-type-502.html</ref>
      <ref url="http://secunia.com/advisories/39741" source="SECUNIA" adv="1">39741</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000017.html" source="JVNDB">JVNDB-2010-000017</ref>
      <ref url="http://jvn.jp/en/jp/JVN92854093/index.html" source="JVN">JVN#92854093</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixapart" name="movable_type">
        <vers num="5.0" />
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1986" published="2010-05-20" name="CVE-2010-1986" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends long strings to the content of a P element, related to the gfxWindowsFontGroup::MakeTextRun function in xul.dll, a different vulnerability than CVE-2009-1571.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58761" source="XF">firefox-javascriptcode-dos(58761)</ref>
      <ref url="http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt" source="MISC">http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511329/100/0/threaded" source="BUGTRAQ">20100518 Firefox 3.6.3 (latest) &lt;= memory exhaustion crash vulnerabilities</ref>
      <ref url="http://www.osvdb.org/64791" source="OSVDB">64791</ref>
      <ref url="http://www.exploit-db.com/exploits/12678" source="EXPLOIT-DB">12678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12433" source="OVAL">oval:org.mitre.oval:def:12433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1987" published="2010-05-20" name="CVE-2010-1987" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs certain other string concatenation and substring operations, related to the DoubleWideCharMappedString class in USP10.dll and the gfxWindowsFontGroup::GetUnderlineOffset function in xul.dll, a different vulnerability than CVE-2009-1571.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58762" source="XF">firefox-pelement-dos(58762)</ref>
      <ref url="http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt" source="MISC">http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511329/100/0/threaded" source="BUGTRAQ">20100518 Firefox 3.6.3 (latest) &lt;= memory exhaustion crash vulnerabilities</ref>
      <ref url="http://www.exploit-db.com/exploits/12678" source="EXPLOIT-DB">12678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12013" source="OVAL">oval:org.mitre.oval:def:12013</ref>
      <ref url="http://osvdb.org/64790" source="OSVDB">64790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1988" published="2010-05-20" name="CVE-2010-1988" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via JavaScript code that performs certain string concatenation and substring operations, a different vulnerability than CVE-2009-1571.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58763" source="XF">firefox-substring-code-execution(58763)</ref>
      <ref url="http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt" source="MISC">http://www.x90c.org/advisories/firefox_3.6.3_crash_advisory.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511329/100/0/threaded" source="BUGTRAQ">20100518 Firefox 3.6.3 (latest) &lt;= memory exhaustion crash vulnerabilities</ref>
      <ref url="http://www.exploit-db.com/exploits/12678" source="EXPLOIT-DB">12678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12050" source="OVAL">oval:org.mitre.oval:def:12050</ref>
      <ref url="http://osvdb.org/64789" source="OSVDB">64789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1989" published="2010-05-20" name="CVE-2010-1989" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 9.52 executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images, a related issue to CVE-2010-0181.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11664" source="OVAL">oval:org.mitre.oval:def:11664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="9.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1990" published="2010-05-20" name="CVE-2010-1990" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12386" source="OVAL">oval:org.mitre.oval:def:12386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers prev="1" num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1991" published="2010-05-20" name="CVE-2010-1991" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6.0.2900.2180" />
        <vers num="7" />
        <vers num="7.0" />
        <vers num="8.0.7600.16385" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1992" published="2010-05-20" name="CVE-2010-1992" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11363" source="OVAL">oval:org.mitre.oval:def:11363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1993" published="2010-05-20" name="CVE-2010-1993" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (resource consumption) via an HTML document with many IFRAME elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511327/100/0/threaded" source="BUGTRAQ">20100518 DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers</ref>
      <ref url="http://websecurity.com.ua/4206/" source="MISC">http://websecurity.com.ua/4206/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11952" source="OVAL">oval:org.mitre.oval:def:11952</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="9.52" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-1994" published="2010-05-20" name="CVE-2010-1994" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58470" source="XF">tomatocms-index-sql-injection(58470)</ref>
      <ref url="http://www.securityfocus.com/bid/40108" source="BID">40108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511273/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: TomatoCMS "q" SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2010-56" source="MISC" adv="1">http://secunia.com/secunia_research/2010-56</ref>
      <ref url="http://secunia.com/advisories/39320" source="SECUNIA" adv="1">39320</ref>
      <ref url="http://osvdb.org/64551" source="OSVDB">64551</ref>
      <ref url="http://holisticinfosec.org/content/view/141/45/" source="MISC">http://holisticinfosec.org/content/view/141/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomatocms" name="tomatocms">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.3.1430" />
        <vers num="2.0.3.1622" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1995" published="2010-05-20" name="CVE-2010-1995" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new article" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58471" source="XF">tomatocms-index-title-xss(58471)</ref>
      <ref url="http://www.securityfocus.com/bid/40108" source="BID">40108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511272/100/0/threaded" source="BUGTRAQ">20100512 Secunia Research: TomatoCMS Script Insertion Vulnerabilities</ref>
      <ref url="http://secunia.com/secunia_research/2010-59/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-59/</ref>
      <ref url="http://secunia.com/advisories/39320" source="SECUNIA" adv="1">39320</ref>
      <ref url="http://osvdb.org/64550" source="OSVDB">64550</ref>
      <ref url="http://holisticinfosec.org/content/view/141/45/" source="MISC">http://holisticinfosec.org/content/view/141/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomatocms" name="tomatocms">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.3.1430" />
        <vers num="2.0.3.1622" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1996" published="2010-05-20" name="CVE-2010-1996" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with a /admin/category/add PATH_INFO, and the (3) keyword parameter in conjunction with a /admin/tag/add PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58492" source="XF">tomatocms-index-keyword-xss(58492)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58491" source="XF">tomatocms-index-meta-xss(58491)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58475" source="XF">tomatocms-index-content-xss(58475)</ref>
      <ref url="http://www.securityfocus.com/bid/40108" source="BID">40108</ref>
      <ref url="http://secunia.com/advisories/39320" source="SECUNIA" adv="1">39320</ref>
      <ref url="http://osvdb.org/64554" source="OSVDB">64554</ref>
      <ref url="http://osvdb.org/64553" source="OSVDB">64553</ref>
      <ref url="http://osvdb.org/64552" source="OSVDB">64552</ref>
      <ref url="http://holisticinfosec.org/content/view/141/45/" source="MISC">http://holisticinfosec.org/content/view/141/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tomatocms" name="tomatocms">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.3.1430" />
        <vers num="2.0.3.1622" />
        <vers prev="1" num="2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1997" published="2010-05-20" name="CVE-2010-1997" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40059" source="BID">40059</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511223/100/0/threaded" source="BUGTRAQ">20100511 XSS in Saurus CMS</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_in_saurus_cms.html" source="MISC">http://www.htbridge.ch/advisory/xss_in_saurus_cms.html</ref>
      <ref url="http://secunia.com/advisories/39773" source="SECUNIA" adv="1">39773</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/sauruscms-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/sauruscms-xss.txt</ref>
      <ref url="http://osvdb.org/64570" source="OSVDB">64570</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saurus" name="saurus_cms">
        <vers num="4.7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-1998" published="2010-05-20" name="CVE-2010-1998" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1080" source="VUPEN" patch="1" adv="1">ADV-2010-1080</ref>
      <ref url="http://drupal.org/node/790998" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/790998</ref>
      <ref url="http://drupal.org/node/790364" source="CONFIRM" patch="1">http://drupal.org/node/790364</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58353" source="XF">ccktablefield-tableheaders-xss(58353)</ref>
      <ref url="http://www.securityfocus.com/bid/39954" source="BID">39954</ref>
      <ref url="http://www.osvdb.org/64358" source="OSVDB">64358</ref>
      <ref url="http://secunia.com/advisories/39644" source="SECUNIA" adv="1">39644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kevinhankens" name="tablefield">
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-1999" published="2010-05-20" name="CVE-2010-1999" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1051" source="VUPEN" adv="1">ADV-2010-1051</ref>
      <ref url="http://www.osvdb.org/64183" source="OSVDB">64183</ref>
      <ref url="http://www.exploit-db.com/exploits/12475" source="EXPLOIT-DB">12475</ref>
      <ref url="http://secunia.com/advisories/39688" source="SECUNIA" adv="1">39688</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/opencatalogue-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/opencatalogue-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openmairie" name="opencatalogue">
        <vers num="1.024" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2000" published="2010-05-20" name="CVE-2010-2000" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1358.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40127" source="BID" patch="1">40127</ref>
      <ref url="http://drupal.org/node/797192" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/797192</ref>
      <ref url="http://drupal.org/node/796502" source="CONFIRM" patch="1">http://drupal.org/node/796502</ref>
      <ref url="http://drupal.org/node/796498" source="CONFIRM" patch="1">http://drupal.org/node/796498</ref>
      <ref url="http://secunia.com/advisories/39810" source="SECUNIA" adv="1">39810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ron_jerome" name="bibliography">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.10" />
        <vers num="5.x-1.11" />
        <vers num="5.x-1.12" />
        <vers num="5.x-1.13" />
        <vers num="5.x-1.14" />
        <vers num="5.x-1.15" />
        <vers num="5.x-1.16" />
        <vers num="5.x-1.17" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.0" edition="rc2" />
        <vers num="6.x-1.0" edition="rc3" />
        <vers num="6.x-1.0" edition="rc4" />
        <vers num="6.x-1.0" edition="rc5" />
        <vers num="6.x-1.0-beta1" />
        <vers num="6.x-1.0-beta2" />
        <vers num="6.x-1.0-beta3" />
        <vers num="6.x-1.0-beta4" />
        <vers num="6.x-1.0-beta5" />
        <vers num="6.x-1.0-beta6" />
        <vers num="6.x-1.0-beta7" />
        <vers num="6.x-1.0-beta8" />
        <vers num="6.x-1.0-beta9" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.5" />
        <vers num="6.x-1.6" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2001" published="2010-05-20" name="CVE-2010-2001" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the CiviRegister module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40130" source="BID" patch="1">40130</ref>
      <ref url="http://drupal.org/node/797352" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/797352</ref>
      <ref url="http://drupal.org/node/797342" source="CONFIRM" patch="1">http://drupal.org/node/797342</ref>
      <ref url="http://secunia.com/advisories/39806" source="SECUNIA" adv="1">39806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjitsuweb" name="civiregister">
        <vers num="6.x-1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2002" published="2010-05-20" name="CVE-2010-2002" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40119" source="BID" patch="1">40119</ref>
      <ref url="http://drupal.org/node/797208" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/797208</ref>
      <ref url="http://drupal.org/node/796620" source="CONFIRM" patch="1">http://drupal.org/node/796620</ref>
      <ref url="http://drupal.org/node/796618" source="CONFIRM" patch="1">http://drupal.org/node/796618</ref>
      <ref url="http://secunia.com/advisories/39811" source="SECUNIA" adv="1">39811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="addison_berry" name="wordfilter">
        <vers num="5.x-1.x" edition="dev" />
      </prod>
      <prod vendor="jeff_warrington" name="wordfilter">
        <vers num="5.x-1.0" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2003" published="2010-05-20" name="CVE-2010-2003" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject arbitrary web script or HTML via the mysql_host parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58503" source="XF">advancedpoll-getadmin-xss(58503)</ref>
      <ref url="http://www.securityfocus.com/bid/40045" source="BID">40045</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511210/100/0/threaded" source="BUGTRAQ">20100510 XSS vulnerability in Advanced Poll</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_advanced_poll.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_advanced_poll.html</ref>
      <ref url="http://secunia.com/advisories/39768" source="SECUNIA" adv="1">39768</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/advancedpoll208-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/advancedpoll208-xss.txt</ref>
      <ref url="http://osvdb.org/64524" source="OSVDB">64524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proxy2" name="advanced_poll">
        <vers num="2.08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2004" published="2010-05-20" name="CVE-2010-2004" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via the Skin parameter in the Options section of a skins file (.bsi), a different vulnerability than CVE-2009-1068.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55708" source="XF">bsplayer-bsi-bo(55708)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0148" source="VUPEN" adv="1">ADV-2010-0148</ref>
      <ref url="http://www.securityfocus.com/bid/37831" source="BID">37831</ref>
      <ref url="http://www.mertsarica.com/codes/bsplayer_seh_overwrite.py" source="MISC">http://www.mertsarica.com/codes/bsplayer_seh_overwrite.py</ref>
      <ref url="http://www.mertsarica.com/?p=511" source="MISC">http://www.mertsarica.com/?p=511</ref>
      <ref url="http://www.exploit-db.com/exploits/11154" source="EXPLOIT-DB">11154</ref>
      <ref url="http://secunia.com/advisories/38221" source="SECUNIA" adv="1">38221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsplayer" name="bs.player">
        <vers num="2.51" edition="-" />
        <vers num="2.51" edition="-:free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2005" published="2010-05-20" name="CVE-2010-2005" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/include/init.php, (2) the config[langs] parameter to engine/inc/help.php, (3) the config[lang] parameter to engine/ajax/pm.php, (4) and the _REQUEST[skin] parameter to engine/ajax/addcomments.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/55757" source="XF">datalife-multiple-file-include(55757)</ref>
      <ref url="http://www.securityfocus.com/bid/37851" source="BID">37851</ref>
      <ref url="http://www.packetstormsecurity.com/1001-exploits/datalifeengine83-rfi.txt" source="MISC">http://www.packetstormsecurity.com/1001-exploits/datalifeengine83-rfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="datalifecms" name="datalife_engine">
        <vers num="8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2006" published="2010-05-20" name="CVE-2010-2006" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20100115-0_mydms_file_inclusion.txt" source="MISC">https://www.sec-consult.com/files/20100115-0_mydms_file_inclusion.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55709" source="XF">letodms-oplogin-file-include(55709)</ref>
      <ref url="http://www.securityfocus.com/bid/37828" source="BID">37828</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508947/100/0/threaded" source="BUGTRAQ">20100115 SEC Consult SA-20100115-0 :: Local file inclusion/execution and multiple CSRF vulnerabilities in LetoDMS (formerly MyDMS)</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2146" source="DEBIAN">DSA-2146</ref>
      <ref url="http://secunia.com/advisories/42900" source="SECUNIA">42900</ref>
      <ref url="http://secunia.com/advisories/38237" source="SECUNIA" adv="1">38237</ref>
      <ref url="http://osvdb.org/61834" source="OSVDB">61834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="letodms" name="letodms">
        <vers num="1.5.0" edition="b" />
        <vers num="1.5.1" />
        <vers num="1.6.0" edition="b" />
        <vers num="1.7.0" />
        <vers prev="1" num="1.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2007" published="2010-05-20" name="CVE-2010-2007" modified="2010-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that use (1) op/op.EditUserData.php, (2) op/op.UsrMgr.php, (3) out/out.RemoveVersion.php, (4) op/op.RemoveFolder.php, (5) op/op.DefaultKeywords.php, (6) op/op.GroupMgr.php, (7) op/op.FolderAccess.php, (8) op/op.FolderNotify.php, or (9) op.MoveFolder.php in mydms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.sec-consult.com/files/20100115-0_mydms_file_inclusion.txt" source="MISC">https://www.sec-consult.com/files/20100115-0_mydms_file_inclusion.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/55710" source="XF">letodms-multiple-csrf(55710)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508947/100/0/threaded" source="BUGTRAQ">20100115 SEC Consult SA-20100115-0 :: Local file inclusion/execution and multiple CSRF vulnerabilities in LetoDMS (formerly MyDMS)</ref>
      <ref url="http://secunia.com/advisories/38237" source="SECUNIA" adv="1">38237</ref>
      <ref url="http://osvdb.org/61835" source="OSVDB">61835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="letodms" name="letodms">
        <vers num="1.5.0" edition="b" />
        <vers num="1.5.1" />
        <vers num="1.6.0" edition="b" />
        <vers num="1.7.0" />
        <vers prev="1" num="1.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2008" published="2010-07-13" name="CVE-2010-2008" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1918" source="VUPEN">ADV-2010-1918</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1017-1" source="UBUNTU">USN-1017-1</ref>
      <ref url="http://www.securitytracker.com/id?1024160" source="SECTRACK">1024160</ref>
      <ref url="http://www.securityfocus.com/bid/41198" source="BID">41198</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:155" source="MANDRIVA">MDVSA-2010:155</ref>
      <ref url="http://secunia.com/advisories/40762" source="SECUNIA">40762</ref>
      <ref url="http://secunia.com/advisories/40333" source="SECUNIA" adv="1">40333</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11869" source="OVAL">oval:org.mitre.oval:def:11869</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044546.html" source="FEDORA">FEDORA-2010-11135</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.html" source="CONFIRM">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-48.html</ref>
      <ref url="http://bugs.mysql.com/bug.php?id=53804" source="CONFIRM">http://bugs.mysql.com/bug.php?id=53804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.15" />
        <vers num="5.1.16" />
        <vers num="5.1.17" />
        <vers num="5.1.18" />
        <vers num="5.1.19" />
        <vers num="5.1.2" />
        <vers num="5.1.20" />
        <vers num="5.1.21" />
        <vers num="5.1.22" />
        <vers num="5.1.23" edition="a" />
        <vers num="5.1.23_bk" />
        <vers num="5.1.23a" />
        <vers num="5.1.24" />
        <vers num="5.1.25" />
        <vers num="5.1.26" />
        <vers num="5.1.27" />
        <vers num="5.1.28" />
        <vers num="5.1.29" />
        <vers num="5.1.3" />
        <vers num="5.1.30" />
        <vers num="5.1.31" edition="sp1" />
        <vers num="5.1.32" />
        <vers num="5.1.32-bzr" />
        <vers num="5.1.33" />
        <vers num="5.1.34" edition="sp1" />
        <vers num="5.1.35" />
        <vers num="5.1.36" />
        <vers num="5.1.37" edition="sp1" />
        <vers num="5.1.38" />
        <vers num="5.1.39" />
        <vers num="5.1.4" />
        <vers num="5.1.40" edition="sp1" />
        <vers num="5.1.41" />
        <vers num="5.1.42" />
        <vers num="5.1.43" edition="sp1" />
        <vers num="5.1.44" />
        <vers num="5.1.45" />
        <vers num="5.1.46" edition="sp1" />
        <vers prev="1" num="5.1.47" />
        <vers num="5.1.5" />
        <vers num="5.1.5a" />
        <vers num="5.1.6" />
        <vers num="5.1.7" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2009" published="2010-05-21" name="CVE-2010-2009" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the media library in BS.Global BS.Player 2.51 build 1022, 2.41 build 1003, and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long ID3 tag in a .MP3 file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4932.php" source="MISC">http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4932.php</ref>
      <ref url="http://www.securityfocus.com/bid/38568" source="BID">38568</ref>
      <ref url="http://www.packetstormsecurity.org/1003-advisories/bsplayerml-overflow.txt" source="MISC">http://www.packetstormsecurity.org/1003-advisories/bsplayerml-overflow.txt</ref>
      <ref url="http://secunia.com/advisories/38221" source="SECUNIA" adv="1">38221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsplayer" name="bs.player">
        <vers num="2.41" />
        <vers num="2.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2010" published="2010-05-21" name="CVE-2010-2010" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40285" source="BID" patch="1">40285</ref>
      <ref url="http://drupal.org/node/803944" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/803944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58721" source="XF">chaos-tool-titles-xss(58721)</ref>
      <ref url="http://secunia.com/advisories/39884" source="SECUNIA" adv="1">39884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="angrydonuts" name="ctools">
        <vers num="6.x-1.0" edition="alpha1" />
        <vers num="6.x-1.0" edition="alpha2" />
        <vers num="6.x-1.0" edition="alpha3" />
        <vers num="6.x-1.0" edition="beta1" />
        <vers num="6.x-1.0" edition="beta2" />
        <vers num="6.x-1.0" edition="beta3" />
        <vers num="6.x-1.0" edition="beta4" />
        <vers num="6.x-1.0" edition="rc1" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2011" published="2010-05-21" name="CVE-2010-2011" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain sensitive information by decrypting a field's contents.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.christopherkois.com/?p=448" source="MISC">http://www.christopherkois.com/?p=448</ref>
      <ref url="http://slashdot.org/story/10/05/21/1437227" source="MISC">http://slashdot.org/story/10/05/21/1437227</ref>
      <ref url="http://blogs.msdn.com/developingfordynamicsgp/archive/2008/10/02/why-does-microsoft-dynamics-gp-encrypt-passwords.aspx" source="MISC">http://blogs.msdn.com/developingfordynamicsgp/archive/2008/10/02/why-does-microsoft-dynamics-gp-encrypt-passwords.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="dynamics_gp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2012" published="2010-05-24" name="CVE-2010-2012" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in function.php in MigasCMS 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categorie parameter in a catalogo action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40256" source="BID">40256</ref>
      <ref url="http://www.itsecteam.com/en/vulnerabilities/vulnerability54.htm" source="MISC">http://www.itsecteam.com/en/vulnerabilities/vulnerability54.htm</ref>
      <ref url="http://secunia.com/advisories/39878" source="SECUNIA" adv="1">39878</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/migascms-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/migascms-sql.txt</ref>
      <ref url="http://osvdb.org/64732" source="OSVDB">64732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sebrac.webcindario" name="migascms">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2013" published="2010-05-24" name="CVE-2010-2013" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511379/100/0/threaded" source="BUGTRAQ">20100520 XSS vulnerability in LiSK CMS</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_product.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_product.html</ref>
      <ref url="http://secunia.com/advisories/39912" source="SECUNIA" adv="1">39912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="createch-group" name="lisk_cms">
        <vers num="4.4" edition="-" />
        <vers num="4.4" edition="-:portal/community" />
        <vers num="4.4" edition="-:e-commerce" />
        <vers num="4.4" edition="-:custom" />
        <vers num="4.4" edition="-:extranet/intranet" />
        <vers num="4.4" edition="-:corporate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2014" published="2010-05-24" name="CVE-2010-2014" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_lisk_cms.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_lisk_cms.html</ref>
      <ref url="http://secunia.com/advisories/39912" source="SECUNIA" adv="1">39912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="createch-group" name="lisk_cms">
        <vers num="4.4" edition="-" />
        <vers num="4.4" edition="-:portal/community" />
        <vers num="4.4" edition="-:e-commerce" />
        <vers num="4.4" edition="-:custom" />
        <vers num="4.4" edition="-:extranet/intranet" />
        <vers num="4.4" edition="-:corporate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2015" published="2010-05-24" name="CVE-2010-2015" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_lisk_cms_1.html" source="MISC">http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_lisk_cms_1.html</ref>
      <ref url="http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_lisk_cms.html" source="MISC">http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_lisk_cms.html</ref>
      <ref url="http://secunia.com/advisories/39912" source="SECUNIA" adv="1">39912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="createch-group" name="lisk_cms">
        <vers num="4.4" edition="-" />
        <vers num="4.4" edition="-:portal/community" />
        <vers num="4.4" edition="-:e-commerce" />
        <vers num="4.4" edition="-:custom" />
        <vers num="4.4" edition="-:extranet/intranet" />
        <vers num="4.4" edition="-:corporate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2016" published="2010-05-24" name="CVE-2010-2016" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58617" source="XF">icebergcms-details-sql-injection(58617)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1161" source="VUPEN" adv="1">ADV-2010-1161</ref>
      <ref url="http://www.osvdb.org/64694" source="OSVDB">64694</ref>
      <ref url="http://www.exploit-db.com/exploits/12620" source="EXPLOIT-DB">12620</ref>
      <ref url="http://secunia.com/advisories/39833" source="SECUNIA" adv="1">39833</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/iceberg-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/iceberg-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagetraders" name="iceberg_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2017" published="2010-05-24" name="CVE-2010-2017" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to inject arbitrary web script or HTML via the kata parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39863" source="SECUNIA" adv="1">39863</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/lokomediacms-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/lokomediacms-xss.txt</ref>
      <ref url="http://osvdb.org/64748" source="OSVDB">64748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bukulokomedia" name="lokomedia_cms">
        <vers num="1.4.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2018" published="2010-05-24" name="CVE-2010-2018" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58670" source="XF">lokomedia-downlot-directory-traversal(58670)</ref>
      <ref url="http://www.exploit-db.com/exploits/12651" source="EXPLOIT-DB">12651</ref>
      <ref url="http://secunia.com/advisories/39863" source="SECUNIA" adv="1">39863</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/lokomediacms-disclose.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/lokomediacms-disclose.txt</ref>
      <ref url="http://osvdb.org/64747" source="OSVDB">64747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bukulokomedia" name="lokomedia_cms">
        <vers num="1.4.1" />
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2019" published="2010-05-24" name="CVE-2010-2019" modified="2010-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in downlot.php in Lokomedia CMS 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the file parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39863" source="SECUNIA" adv="1">39863</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bukulokomedia" name="lokomedia_cms">
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2020" published="2010-05-28" name="CVE-2010-2020" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1024039" source="SECTRACK">1024039</ref>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-10:06.nfsclient.asc" source="FREEBSD" adv="1">FreeBSD-SA-10:06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="7.2" edition="pre-release" />
        <vers num="7.2" edition="stable" />
        <vers num="8.0" />
        <vers num="8.1-prerelease" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2022" published="2010-05-28" name="CVE-2010-2022" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1247" source="VUPEN" patch="1" adv="1">ADV-2010-1247</ref>
      <ref url="http://www.securityfocus.com/bid/40399" source="BID">40399</ref>
      <ref url="http://securitytracker.com/id?1024038" source="SECTRACK">1024038</ref>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-10:04.jail.asc" source="FREEBSD" adv="1">FreeBSD-SA-10:04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="8.0" />
        <vers num="8.1-prerelease" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2023" published="2010-06-07" name="CVE-2010-2023" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.24&amp;r2=1.25" source="CONFIRM" patch="1">http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.24&amp;r2=1.25</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=600093" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=600093</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59043" source="XF">exim-mail-directory-priv-escalation(59043)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0364" source="VUPEN">ADV-2011-0364</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1402" source="VUPEN">ADV-2010-1402</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1060-1" source="UBUNTU">USN-1060-1</ref>
      <ref url="http://www.securityfocus.com/bid/40451" source="BID">40451</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511653/100/0/threaded" source="BUGTRAQ">20100603 Multiple vulnerabilities in Exim</ref>
      <ref url="http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&amp;pathrev=exim-4_72_RC2" source="CONFIRM">http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&amp;pathrev=exim-4_72_RC2</ref>
      <ref url="http://secunia.com/advisories/43243" source="SECUNIA">43243</ref>
      <ref url="http://secunia.com/advisories/40123" source="SECUNIA">40123</ref>
      <ref url="http://secunia.com/advisories/40019" source="SECUNIA" adv="1">40019</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042613.html" source="FEDORA">FEDORA-2010-9524</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042587.html" source="FEDORA">FEDORA-2010-9506</ref>
      <ref url="http://lists.exim.org/lurker/message/20100524.175925.9a69f755.en.html" source="MLIST">[exim-dev] 20100524 Security issues in exim4 local delivery</ref>
      <ref url="http://bugs.exim.org/show_bug.cgi?id=988" source="CONFIRM">http://bugs.exim.org/show_bug.cgi?id=988</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0079.html" source="FULLDISC">20100603 Multiple vulnerabilities in Exim</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exim" name="exim">
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers num="4.24" />
        <vers num="4.30" />
        <vers num="4.31" />
        <vers num="4.32" />
        <vers num="4.33" />
        <vers num="4.34" />
        <vers num="4.40" />
        <vers num="4.41" />
        <vers num="4.42" />
        <vers num="4.43" />
        <vers num="4.44" />
        <vers num="4.50" />
        <vers num="4.51" />
        <vers num="4.52" />
        <vers num="4.53" />
        <vers num="4.54" />
        <vers num="4.60" />
        <vers num="4.61" />
        <vers num="4.62" />
        <vers num="4.63" />
        <vers num="4.64" />
        <vers num="4.65" />
        <vers num="4.66" />
        <vers num="4.67" />
        <vers num="4.68" />
        <vers num="4.69" />
        <vers num="4.70" />
        <vers prev="1" num="4.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2024" published="2010-06-07" name="CVE-2010-2024" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.25&amp;r2=1.26" source="CONFIRM" patch="1">http://vcs.exim.org/viewvc/exim/exim-src/src/transports/appendfile.c?r1=1.25&amp;r2=1.26</ref>
      <ref url="http://bugs.exim.org/show_bug.cgi?id=989" source="CONFIRM" patch="1">http://bugs.exim.org/show_bug.cgi?id=989</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=600097" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=600097</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59042" source="XF">exim-mbx-symlink(59042)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0364" source="VUPEN">ADV-2011-0364</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1402" source="VUPEN">ADV-2010-1402</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1060-1" source="UBUNTU">USN-1060-1</ref>
      <ref url="http://www.securityfocus.com/bid/40454" source="BID">40454</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511653/100/0/threaded" source="BUGTRAQ">20100603 Multiple vulnerabilities in Exim</ref>
      <ref url="http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&amp;pathrev=exim-4_72_RC2" source="CONFIRM">http://vcs.exim.org/viewvc/exim/exim-doc/doc-txt/ChangeLog?view=markup&amp;pathrev=exim-4_72_RC2</ref>
      <ref url="http://secunia.com/advisories/43243" source="SECUNIA">43243</ref>
      <ref url="http://secunia.com/advisories/40123" source="SECUNIA">40123</ref>
      <ref url="http://secunia.com/advisories/40019" source="SECUNIA" adv="1">40019</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042613.html" source="FEDORA">FEDORA-2010-9524</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042587.html" source="FEDORA">FEDORA-2010-9506</ref>
      <ref url="http://lists.exim.org/lurker/message/20100524.175925.9a69f755.en.html" source="MLIST">[exim-dev] 20100524 Security issues in exim4 local delivery</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-06/0079.html" source="FULLDISC">20100603 Multiple vulnerabilities in Exim</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exim" name="exim">
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers num="4.24" />
        <vers num="4.30" />
        <vers num="4.31" />
        <vers num="4.32" />
        <vers num="4.33" />
        <vers num="4.34" />
        <vers num="4.40" />
        <vers num="4.41" />
        <vers num="4.42" />
        <vers num="4.43" />
        <vers num="4.44" />
        <vers num="4.50" />
        <vers num="4.51" />
        <vers num="4.52" />
        <vers num="4.53" />
        <vers num="4.54" />
        <vers num="4.60" />
        <vers num="4.61" />
        <vers num="4.62" />
        <vers num="4.63" />
        <vers num="4.64" />
        <vers num="4.65" />
        <vers num="4.66" />
        <vers num="4.67" />
        <vers num="4.68" />
        <vers num="4.69" />
        <vers num="4.70" />
        <vers prev="1" num="4.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2025" published="2010-05-26" name="CVE-2010-2025" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change the administrative password, (4) install modified firmware, or (5) change the access level, as demonstrated by a request to goform/_aslvl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40346" source="BID">40346</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0322.html" source="FULLDISC">20100524 Scientific Atlanta DPC2100 WebSTAR Cable Modem vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="scientific_atlanta_webstar_dpc2100r2">
        <vers num="2.0.2r1256-060303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2026" published="2010-05-26" name="CVE-2010-2026" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40346" source="BID">40346</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0322.html" source="FULLDISC">20100524 Scientific Atlanta DPC2100 WebSTAR Cable Modem vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="scientific_atlanta_webstar_dpc2100r2">
        <vers num="2.0.2r1256-060303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2027" published="2010-05-24" name="CVE-2010-2027" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511298/100/0/threaded" source="BUGTRAQ">20100514 Mathematica on Linux /tmp/MathLink vulnerability</ref>
      <ref url="http://secunia.com/advisories/39805" source="SECUNIA" adv="1">39805</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=127380255201760&amp;w=2" source="FULLDISC">20100514 Mathematica on Linux /tmp/MathLink vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wolfram_research" name="mathematica">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2028" published="2010-05-24" name="CVE-2010-2028" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58283" source="XF">tftpgui-mode-bo(58283)</ref>
      <ref url="http://www.securityfocus.com/bid/39872" source="BID">39872</ref>
      <ref url="http://www.exploit-db.com/exploits/12530" source="EXPLOIT-DB">12530</ref>
      <ref url="http://www.exploit-db.com/exploits/12482" source="EXPLOIT-DB">12482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mgenti" name="tftputil_gui">
        <vers num="1.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2029" published="2010-05-24" name="CVE-2010-2029" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/57976" source="XF">cybozu-office-dotsales-sec-bypass(57976)</ref>
      <ref url="http://www.osvdb.org/63933" source="OSVDB">63933</ref>
      <ref url="http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html" source="MISC">http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html</ref>
      <ref url="http://secunia.com/advisories/39508" source="SECUNIA" adv="1">39508</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html" source="JVNDB">JVNDB-2010-000016</ref>
      <ref url="http://jvn.jp/en/jp/JVN87730223/index.html" source="JVN">JVN#87730223</ref>
      <ref url="http://cybozu.co.jp/products/dl/notice/detail/0034.html" source="CONFIRM">http://cybozu.co.jp/products/dl/notice/detail/0034.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybozu" name="cybozu_dotsales">
        <vers num="" />
      </prod>
      <prod vendor="cybozu" name="cybozu_office">
        <vers num="7" edition="-" />
        <vers num="7" edition="-:ktai" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2030" published="2010-05-24" name="CVE-2010-2030" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the External Link Page module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the administration and redirect pages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/803766" source="CONFIRM" patch="1">http://drupal.org/node/803766</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58714" source="XF">externallinkpage-redirect-xss(58714)</ref>
      <ref url="http://secunia.com/advisories/39888" source="SECUNIA" adv="1">39888</ref>
      <ref url="http://osvdb.org/64762" source="OSVDB">64762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alan_palazzolo" name="external_link_page">
        <vers num="5.x-0.8" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2031" published="2010-05-24" name="CVE-2010-2031" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58780" source="XF">webshield-kavsafe-privilege-escalation(58780)</ref>
      <ref url="http://www.securityfocus.com/bid/40342" source="BID">40342</ref>
      <ref url="http://www.exploit-db.com/exploits/12710" source="EXPLOIT-DB">12710</ref>
      <ref url="http://secunia.com/advisories/39916" source="SECUNIA" adv="1">39916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kingsoft" name="webshield">
        <vers prev="1" num="3.5.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2032" published="2010-05-24" name="CVE-2010-2032" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58733" source="XF">caucho-resin-digest-xss(58733)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1201" source="VUPEN" adv="1">ADV-2010-1201</ref>
      <ref url="http://www.securityfocus.com/bid/40251" source="BID">40251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511341/100/0/threaded" source="BUGTRAQ">20100518 Caucho Technology Resin digest.php Cross Site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/39839" source="SECUNIA" adv="1">39839</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/cauchoresin312-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/cauchoresin312-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="caucho" name="resin">
        <vers num="3.1.10" edition="-" />
        <vers num="3.1.10" edition="-:pro" />
        <vers num="3.1.5" edition="-" />
        <vers num="3.1.5" edition="-:pro" />
        <vers num="4.0.6" edition="-" />
        <vers num="4.0.6" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2033" published="2010-05-25" name="CVE-2010-2033" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40244" source="BID">40244</ref>
      <ref url="http://secunia.com/advisories/39873" source="SECUNIA" adv="1">39873</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaperchact-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaperchact-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchacategoriestree">
        <vers num="0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2034" published="2010-05-25" name="CVE-2010-2034" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40244" source="BID">40244</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaperchaia-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaperchaia-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchaimageattach">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2035" published="2010-05-25" name="CVE-2010-2035" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40244" source="BID">40244</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaperchagl-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaperchagl-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchagallery">
        <vers num="1.6" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2036" published="2010-05-25" name="CVE-2010-2036" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40244" source="BID">40244</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaperchafa-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaperchafa-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchafieldsattach">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2037" published="2010-05-25" name="CVE-2010-2037" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40244" source="BID">40244</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaperchada-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaperchada-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="percha" name="com_perchadownloadsattach">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2038" published="2010-05-25" name="CVE-2010-2038" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40330" source="BID" patch="1">40330</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511388/100/0/threaded" source="BUGTRAQ">20100520 XSS vulnerability in gpEasy CMS</ref>
      <ref url="http://www.htbridge.ch/advisory/xss_vulnerability_in_gpeasy_cms.html" source="MISC">http://www.htbridge.ch/advisory/xss_vulnerability_in_gpeasy_cms.html</ref>
      <ref url="http://secunia.com/advisories/39643" source="SECUNIA" adv="1">39643</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/gpeasycms-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/gpeasycms-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gpeasy" name="gpeasy_cms">
        <vers num="1.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2039" published="2010-05-25" name="CVE-2010-2039" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58214" source="XF">gpeasy-admin-interface-csrf(58214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1030" source="VUPEN" adv="1">ADV-2010-1030</ref>
      <ref url="http://www.osvdb.org/64130" source="OSVDB">64130</ref>
      <ref url="http://www.exploit-db.com/exploits/12441" source="EXPLOIT-DB">12441</ref>
      <ref url="http://secunia.com/advisories/39643" source="SECUNIA" adv="1">39643</ref>
      <ref url="http://packetstormsecurity.org/1004-exploits/gpeasy-xsrf.txt" source="MISC">http://packetstormsecurity.org/1004-exploits/gpeasy-xsrf.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gpeasy" name="gpeasy_cms">
        <vers num="1.5" edition="rc2" />
        <vers num="1.5" edition="rc3" />
        <vers num="1.5" edition="rc4" />
        <vers num="1.6" edition="rc1" />
        <vers num="1.6" edition="rc2" />
        <vers num="1.6" edition="rc3" />
        <vers num="1.6" edition="rc4" />
        <vers num="1.6" edition="rc5" />
        <vers num="1.6.1" />
        <vers prev="1" num="1.6.2" />
        <vers num="1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2040" published="2010-05-25" name="CVE-2010-2040" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58749" source="XF">shopzilla-search-xss(58749)</ref>
      <ref url="http://www.securityfocus.com/bid/40246" source="BID">40246</ref>
      <ref url="http://www.packetstormsecurity.org/1005-exploits/shopzillaas-xss.txt" source="MISC">http://www.packetstormsecurity.org/1005-exploits/shopzillaas-xss.txt</ref>
      <ref url="http://secunia.com/advisories/39877" source="SECUNIA" adv="1">39877</ref>
      <ref url="http://osvdb.org/64746" source="OSVDB">64746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="v-eva" name="shopzilla_affiliate_script_php">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2041" published="2010-05-25" name="CVE-2010-2041" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40334" source="BID" patch="1">40334</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58861" source="XF">phpcalendar-description-xss(58861)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1202" source="VUPEN" adv="1">ADV-2010-1202</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511395/100/0/threaded" source="BUGTRAQ">20100521 PHP-Calendar "description" and "lastaction" Cross Site Scripting Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/33899" source="SECUNIA" adv="1">33899</ref>
      <ref url="http://php-calendar.blogspot.com/2010/05/php-calendar-20-beta7.html" source="CONFIRM">http://php-calendar.blogspot.com/2010/05/php-calendar-20-beta7.html</ref>
      <ref url="http://packetstormsecurity.org/1005-advisories/phpcalendar-xss.txt" source="MISC">http://packetstormsecurity.org/1005-advisories/phpcalendar-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-calendar" name="php-calendar">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="1.1" />
        <vers prev="1" num="2.0" edition="beta1" />
        <vers prev="1" num="2.0" edition="beta2" />
        <vers prev="1" num="2.0" edition="beta3" />
        <vers prev="1" num="2.0" edition="beta4" />
        <vers prev="1" num="2.0" edition="beta5" />
        <vers prev="1" num="2.0" edition="beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2042" published="2010-05-25" name="CVE-2010-2042" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40338" source="BID">40338</ref>
      <ref url="http://www.exploit-db.com/exploits/12702" source="EXPLOIT-DB">12702</ref>
      <ref url="http://secunia.com/advisories/39930" source="SECUNIA" adv="1">39930</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/ecshopsearch-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/ecshopsearch-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shopex" name="ecshop">
        <vers num="2.7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2043" published="2010-05-25" name="CVE-2010-2043" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58732" source="XF">datatrack-workordersummary-xss(58732)</ref>
      <ref url="http://www.securityfocus.com/bid/40249" source="BID">40249</ref>
      <ref url="http://secunia.com/advisories/39868" source="SECUNIA" adv="1">39868</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt</ref>
      <ref url="http://osvdb.org/64727" source="OSVDB">64727</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html" source="MISC">http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magnoware" name="datatrack_system">
        <vers num="3.5" />
        <vers num="3.5.8019.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2044" published="2010-05-25" name="CVE-2010-2044" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58584" source="XF">konsultasi-sid-sql-injection(58584)</ref>
      <ref url="http://www.securityfocus.com/bid/40160" source="BID">40160</ref>
      <ref url="http://www.exploit-db.com/exploits/12590" source="EXPLOIT-DB">12590</ref>
      <ref url="http://secunia.com/advisories/39816" source="SECUNIA" adv="1">39816</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlakonsultasi-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlakonsultasi-sql.txt</ref>
      <ref url="http://osvdb.org/64637" source="OSVDB">64637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adhie_utomo" name="com_konsultasi">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2045" published="2010-05-25" name="CVE-2010-2045" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58574" source="XF">dioneformwizard-controller-file-include(58574)</ref>
      <ref url="http://www.securityfocus.com/bid/40166" source="BID">40166</ref>
      <ref url="http://www.exploit-db.com/exploits/12595" source="EXPLOIT-DB">12595</ref>
      <ref url="http://secunia.com/advisories/39755" source="SECUNIA" adv="1">39755</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlafdione-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlafdione-lfi.txt</ref>
      <ref url="http://osvdb.org/64633" source="OSVDB">64633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dionesoft" name="com_dioneformwizard">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2046" published="2010-05-25" name="CVE-2010-2046" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER parameter to server/index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xenuser.org/documents/security/joomla_com_activehelper_livehelp_xss.txt" source="MISC">http://xenuser.org/documents/security/joomla_com_activehelper_livehelp_xss.txt</ref>
      <ref url="http://www.xenuser.org/2010/05/19/joomla-component-activehelper-livehelp-xss-vulnerabilities/" source="MISC">http://www.xenuser.org/2010/05/19/joomla-component-activehelper-livehelp-xss-vulnerabilities/</ref>
      <ref url="http://www.securityfocus.com/bid/40278" source="BID">40278</ref>
      <ref url="http://secunia.com/advisories/39870" source="SECUNIA" adv="1">39870</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlaactivehelper-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlaactivehelper-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activehelper" name="com_activehelper_livehelp">
        <vers num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2047" published="2010-05-25" name="CVE-2010-2047" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58646" source="XF">jecms-index-sql-injection(58646)</ref>
      <ref url="http://www.securityfocus.com/bid/40231" source="BID">40231</ref>
      <ref url="http://www.exploit-db.com/exploits/12641" source="EXPLOIT-DB">12641</ref>
      <ref url="http://secunia.com/advisories/39851" source="SECUNIA" adv="1">39851</ref>
      <ref url="http://osvdb.org/64716" source="OSVDB">64716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joenasejes" name="je_cms">
        <vers num="1.0.0" />
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2048" published="2010-05-25" name="CVE-2010-2048" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40268" source="BID" patch="1">40268</ref>
      <ref url="http://drupal.org/node/803570" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/803570</ref>
      <ref url="http://drupal.org/node/802508" source="CONFIRM" patch="1">http://drupal.org/node/802508</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/58702" source="XF">heartbeat-unspecified-xss(58702)</ref>
      <ref url="http://secunia.com/advisories/39893" source="SECUNIA" adv="1">39893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="menhir" name="heartbeat">
        <vers num="6.x-2.3" edition="beta1" />
        <vers num="6.x-2.3" edition="beta2" />
        <vers num="6.x-3.2" />
        <vers num="6.x-3.3" />
        <vers num="6.x-3.x" edition="dev" />
        <vers num="6.x-4.0" />
        <vers num="6.x-4.1" />
        <vers num="6.x-4.2" />
        <vers num="6.x-4.3" edition="beta1" />
        <vers num="6.x-4.3" edition="beta2" />
        <vers num="6.x-4.3" edition="beta3" />
        <vers num="6.x-4.4" />
        <vers num="6.x-4.5" />
        <vers num="6.x-4.6" />
        <vers num="6.x-4.7" />
        <vers num="6.x-4.8" />
        <vers num="6.x-4.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2049" published="2010-05-25" name="CVE-2010-2049" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0 build 4043 allows remote attackers to inject arbitrary web script or HTML via the reportList parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40253" source="BID">40253</ref>
      <ref url="http://secunia.com/advisories/39876" source="SECUNIA" adv="1">39876</ref>
      <ref url="http://osvdb.org/64726" source="OSVDB">64726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="manageengine" name="adaudit_plus">
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2050" published="2010-05-25" name="CVE-2010-2050" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58619" source="XF">mscomment-controller-file-include(58619)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1159" source="VUPEN" adv="1">ADV-2010-1159</ref>
      <ref url="http://www.securityfocus.com/bid/40185" source="BID">40185</ref>
      <ref url="http://www.exploit-db.com/exploits/12611" source="EXPLOIT-DB">12611</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/joomlamscomment-lfi.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/joomlamscomment-lfi.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="m0r0n" name="com_mscomment">
        <vers num="0.8.0" edition="b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2051" published="2010-05-25" name="CVE-2010-2051" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.exploit-db.com/exploits/12661" source="EXPLOIT-DB">12661</ref>
      <ref url="http://secunia.com/advisories/39867" source="SECUNIA" adv="1">39867</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/dbcart-sql.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/dbcart-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debliteck" name="dbcart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-2052" reject="1" published="2010-06-07" name="CVE-2010-2052" modified="2010-06-07">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-2155.  Reason: This candidate is a duplicate of CVE-2010-2155.  Notes: All CVE users should reference CVE-2010-2155 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2053" published="2010-06-07" name="CVE-2010-2053" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://forum.emesene.org/index.php?topic=3441.0" source="CONFIRM" patch="1">http://forum.emesene.org/index.php?topic=3441.0</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59045" source="XF">emesene-emsnpic-symlink(59045)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1423" source="VUPEN">ADV-2010-1423</ref>
      <ref url="http://www.securityfocus.com/bid/40455" source="BID">40455</ref>
      <ref url="http://www.emesene.org/" source="CONFIRM">http://www.emesene.org/</ref>
      <ref url="http://secunia.com/advisories/40115" source="SECUNIA">40115</ref>
      <ref url="http://secunia.com/advisories/39945" source="SECUNIA" adv="1">39945</ref>
      <ref url="http://osvdb.org/65018" source="OSVDB">65018</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127514641525366&amp;w=2" source="MLIST">[oss-security] 20100529 Fwd: emesene preditable temporary filename</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042725.html" source="FEDORA">FEDORA-2010-9679</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042699.html" source="FEDORA">FEDORA-2010-9692</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042683.html" source="FEDORA">FEDORA-2010-9696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emesene" name="emesene">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.5" />
        <vers num="1.5.1" />
        <vers num="1.6" />
        <vers prev="1" num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2054" published="2010-06-15" name="CVE-2010-2054" modified="2010-06-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB 1.3.4 through 1.3.7, when the configuration sets httpMaxContentLength to a zero value, allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a large integer in the Content-Length HTTP header, aka bug #3001915.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1312" source="VUPEN" adv="1">ADV-2010-1312</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=3001915&amp;group_id=128809&amp;atid=712784" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=3001915&amp;group_id=128809&amp;atid=712784</ref>
      <ref url="http://secunia.com/advisories/40018" source="SECUNIA" adv="1">40018</ref>
      <ref url="http://sblim.cvs.sourceforge.net/viewvc/sblim/sfcb/httpAdapter.c?r1=1.85&amp;r2=1.86" source="CONFIRM">http://sblim.cvs.sourceforge.net/viewvc/sblim/sfcb/httpAdapter.c?r1=1.85&amp;r2=1.86</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=127549079109192&amp;w=2" source="MLIST">[oss-security] 20100601 SFCB vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="standards_based_linux_instrumentation" name="sblim-sfcb">
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2055" published="2010-07-22" name="CVE-2010-2055" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=599564" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=599564</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=608071" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=608071</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1757" source="VUPEN" adv="1">ADV-2010-1757</ref>
      <ref url="http://www.securityfocus.com/archive/1/511476" source="BUGTRAQ">20100526 Re: Ghostscript 8.64 executes random code at startup</ref>
      <ref url="http://www.securityfocus.com/archive/1/511474" source="BUGTRAQ">20100526 Re: Ghostscript 8.64 executes random code at startup</ref>
      <ref url="http://www.securityfocus.com/archive/1/511472" source="BUGTRAQ">20100526 Re: Ghostscript 8.64 executes random code at startup</ref>
      <ref url="http://www.securityfocus.com/archive/1/511433" source="BUGTRAQ">20100522 Ghostscript 8.64 executes random code at startup</ref>
      <ref url="http://www.osvdb.org/66247" source="OSVDB">66247</ref>
      <ref url="http://secunia.com/advisories/40532" source="SECUNIA" adv="1">40532</ref>
      <ref url="http://secunia.com/advisories/40475" source="SECUNIA" adv="1">40475</ref>
      <ref url="http://secunia.com/advisories/40452" source="SECUNIA" adv="1">40452</ref>
      <ref url="http://savannah.gnu.org/forum/forum.php?forum_id=6368" source="CONFIRM">http://savannah.gnu.org/forum/forum.php?forum_id=6368</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.html" source="FEDORA">FEDORA-2010-10642</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.html" source="FEDORA">FEDORA-2010-10660</ref>
      <ref url="http://bugs.ghostscript.com/show_bug.cgi?id=691350" source="CONFIRM">http://bugs.ghostscript.com/show_bug.cgi?id=691350</ref>
      <ref url="http://bugs.ghostscript.com/show_bug.cgi?id=691339" source="CONFIRM">http://bugs.ghostscript.com/show_bug.cgi?id=691339</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583316</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=583183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="artifex" name="afpl_ghostscript">
        <vers num="6.0" />
        <vers num="6.01" />
        <vers num="6.50" />
        <vers num="7.00" />
        <vers num="7.03" />
        <vers num="7.04" />
        <vers num="8.00" />
        <vers num="8.11" />
        <vers num="8.12" />
        <vers num="8.13" />
        <vers num="8.14" />
        <vers num="8.50" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
        <vers num="8.54" />
      </prod>
      <prod vendor="artifex" name="ghostscript_fonts">
        <vers num="6.0" />
        <vers num="8.11" />
      </prod>
      <prod vendor="artifex" name="gpl_ghostscript">
        <vers num="8.01" />
        <vers num="8.15" />
        <vers num="8.50" />
        <vers num="8.51" />
        <vers num="8.54" />
        <vers num="8.56" />
        <vers num="8.57" />
        <vers num="8.60" />
        <vers num="8.61" />
        <vers num="8.62" />
        <vers num="8.63" />
        <vers num="8.64" />
        <vers num="8.70" />
        <vers prev="1" num="8.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2056" published="2010-07-22" name="CVE-2010-2056" modified="2010-07-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://savannah.gnu.org/forum/forum.php?forum_id=6368" source="CONFIRM" patch="1" adv="1">http://savannah.gnu.org/forum/forum.php?forum_id=6368</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=599621" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=599621</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1757" source="VUPEN" adv="1">ADV-2010-1757</ref>
      <ref url="http://www.osvdb.org/66249" source="OSVDB">66249</ref>
      <ref url="http://secunia.com/advisories/40532" source="SECUNIA" adv="1">40532</ref>
      <ref url="http://secunia.com/advisories/40475" source="SECUNIA" adv="1">40475</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043948.html" source="FEDORA">FEDORA-2010-10642</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/043913.html" source="FEDORA">FEDORA-2010-10660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gv">
        <vers num="3.5.8" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.6.4" />
        <vers num="3.6.5" />
        <vers num="3.6.6" />
        <vers num="3.6.7" />
        <vers num="3.6.8" />
        <vers prev="1" num="3.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2057" published="2010-10-20" name="CVE-2010-2057" modified="2010-11-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc/myfaces/shared/trunk/core/src/main/java/org/apache/myfaces/shared/util/StateUtils.java?r1=943327&amp;r2=951801" source="CONFIRM" patch="1">http://svn.apache.org/viewvc/myfaces/shared/trunk/core/src/main/java/org/apache/myfaces/shared/util/StateUtils.java?r1=943327&amp;r2=951801</ref>
      <ref url="https://issues.apache.org/jira/browse/MYFACES-2749" source="CONFIRM">https://issues.apache.org/jira/browse/MYFACES-2749</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=623799" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=623799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="myfaces">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2058" published="2010-06-07" name="CVE-2010-2058" modified="2011-02-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">setup.py in Prewikka 0.9.14 installs prewikka.conf with world-readable permissions, which allows local users to obtain the SQL database password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://dev.prelude-technologies.com/projects/prewikka/repository/revisions/17e38c310410be1b7811152172cda4438936063d" source="CONFIRM" patch="1">https://dev.prelude-technologies.com/projects/prewikka/repository/revisions/17e38c310410be1b7811152172cda4438936063d</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/01/13" source="MLIST" patch="1">[oss-security] 20100602 prewikka permission bug</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00771.html" source="FEDORA">FEDORA-2009-3789</ref>
      <ref url="https://dev.prelude-technologies.com/projects/prewikka/repository/revisions/17e38c310410be1b7811152172cda4438936063d/diff/setup.py" source="CONFIRM">https://dev.prelude-technologies.com/projects/prewikka/repository/revisions/17e38c310410be1b7811152172cda4438936063d/diff/setup.py</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=270056" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=270056</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59223" source="XF">prewikka-setup-information-disclosure(59223)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-07.xml" source="GENTOO">GLSA-201101-07</ref>
      <ref url="http://secunia.com/advisories/42820" source="SECUNIA">42820</ref>
    </refs>
    <vuln_soft>
      <prod vendor="prelude-technologies" name="prewikka">
        <vers num="0.9.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2059" published="2010-06-08" name="CVE-2010-2059" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gz" source="CONFIRM" patch="1">http://distrib-coffee.ipsl.jussieu.fr/pub/mirrors/rpm/files/rpm/rpm-4.4/rpm-4.4.3.tar.gz</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=598775" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=598775</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=125517" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=125517</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0606" source="VUPEN">ADV-2011-0606</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0004.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0004.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516909/100/0/threaded" source="BUGTRAQ">20110308 VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0679.html" source="REDHAT">RHSA-2010:0679</ref>
      <ref url="http://www.osvdb.org/65143" source="OSVDB">65143</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/04/1" source="MLIST">[oss-security] 20100604 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/03/5" source="MLIST">[oss-security] 20100603 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/02/3" source="MLIST">[oss-security] 20100602 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/02/2" source="MLIST">[oss-security] 20100602 CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:180" source="MANDRIVA">MDVSA-2010:180</ref>
      <ref url="http://secunia.com/advisories/40028" source="SECUNIA" adv="1">40028</ref>
      <ref url="http://rpm.org/gitweb?p=rpm.git;a=commit;h=ca2d6b2b484f1501eafdde02e1688409340d2383" source="CONFIRM">http://rpm.org/gitweb?p=rpm.git;a=commit;h=ca2d6b2b484f1501eafdde02e1688409340d2383</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127559059928131&amp;w=2" source="MLIST">[oss-security] 20100603 Re: CVE Request -- rpm -- Fails to remove the SUID/SGID bits on package upgrade (RH BZ#598775)</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2011/000126.html" source="MLIST">[security-announce] 20110307 VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rpm" name="rpm">
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.4.2" />
        <vers num="1.4.2/a" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="2..4.10" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.3.10" />
        <vers num="2.2.3.11" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
        <vers num="2.4.1" />
        <vers num="2.4.11" />
        <vers num="2.4.12" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.6.7" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="4.0." />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.1" />
        <vers num="4.3.3" />
        <vers num="4.4.2" />
        <vers num="4.4.2.1" />
        <vers num="4.4.2.2" />
        <vers prev="1" num="4.4.2.3" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.7.0" />
        <vers num="4.7.1" />
        <vers num="4.7.2" />
        <vers num="4.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2060" published="2010-06-07" name="CVE-2010-2060" modified="2010-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The put command functionality in beanstalkd 1.4.5 and earlier allows remote attackers to execute arbitrary Beanstalk commands via the body in a job that is too big, which is not properly handled by the dispatch_cmd function in prot.c.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/77.html

'CWE-77: Improper Sanitization of Special Elements used in a Command ('Command Injection')'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59107" source="XF">beanstalkd-put-command-execution(59107)</ref>
      <ref url="http://www.securityfocus.com/bid/40516" source="BID">40516</ref>
      <ref url="http://secunia.com/advisories/40032" source="SECUNIA" adv="1">40032</ref>
      <ref url="http://osvdb.org/65113" source="OSVDB">65113</ref>
      <ref url="http://kr.github.com/beanstalkd/2010/05/23/1.4.6-release-notes.html" source="CONFIRM">http://kr.github.com/beanstalkd/2010/05/23/1.4.6-release-notes.html</ref>
      <ref url="http://github.com/kr/beanstalkd/commit/2e8e8c6387ecdf5923dfc4d7718d18eba1b0873d" source="CONFIRM">http://github.com/kr/beanstalkd/commit/2e8e8c6387ecdf5923dfc4d7718d18eba1b0873d</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wildbit" name="beanstalkd">
        <vers num="0.10" />
        <vers num="0.5" edition="-" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers prev="1" num="1.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2063" published="2010-06-17" name="CVE-2010-2063" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.samba.org/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch" source="CONFIRM" patch="1">http://www.samba.org/samba/ftp/patches/security/samba-3.3.12-CVE-2010-2063.patch</ref>
      <ref url="http://www.samba.org/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch" source="CONFIRM" patch="1">http://www.samba.org/samba/ftp/patches/security/samba-3.0.37-CVE-2010-2063.patch</ref>
      <ref url="http://marc.info/?l=samba-announce&amp;m=127668712312761&amp;w=2" source="MLIST" patch="1">[samba-announce] 20100616 Samba 3.3.13 Security Release Available for Download</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59481" source="XF">samba-smb1-code-execution(59481)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3063" source="VUPEN">ADV-2010-3063</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1517" source="VUPEN">ADV-2010-1517</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1507" source="VUPEN">ADV-2010-1507</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1505" source="VUPEN">ADV-2010-1505</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1504" source="VUPEN">ADV-2010-1504</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1486" source="VUPEN" adv="1">ADV-2010-1486</ref>
      <ref url="http://www.securitytracker.com/id?1024107" source="SECTRACK">1024107</ref>
      <ref url="http://www.securityfocus.com/bid/40884" source="BID">40884</ref>
      <ref url="http://www.samba.org/samba/security/CVE-2010-2063.html" source="CONFIRM">http://www.samba.org/samba/security/CVE-2010-2063.html</ref>
      <ref url="http://www.samba.org/samba/ftp/history/samba-3.3.13.html" source="CONFIRM">http://www.samba.org/samba/ftp/history/samba-3.3.13.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0488.html" source="REDHAT">RHSA-2010:0488</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:119" source="MANDRIVA">MDVSA-2010:119</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2061" source="DEBIAN">DSA-2061</ref>
      <ref url="http://ubuntu.com/usn/usn-951-1" source="UBUNTU">USN-951-1</ref>
      <ref url="http://support.apple.com/kb/HT4312" source="CONFIRM">http://support.apple.com/kb/HT4312</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.471914" source="SLACKWARE">SSA:2010-169-01</ref>
      <ref url="http://secunia.com/advisories/42319" source="SECUNIA">42319</ref>
      <ref url="http://secunia.com/advisories/40293" source="SECUNIA">40293</ref>
      <ref url="http://secunia.com/advisories/40221" source="SECUNIA">40221</ref>
      <ref url="http://secunia.com/advisories/40210" source="SECUNIA">40210</ref>
      <ref url="http://secunia.com/advisories/40145" source="SECUNIA" adv="1">40145</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9859" source="OVAL">oval:org.mitre.oval:def:9859</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7115" source="OVAL">oval:org.mitre.oval:def:7115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12427" source="OVAL">oval:org.mitre.oval:def:12427</ref>
      <ref url="http://osvdb.org/65518" source="OSVDB">65518</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130835366526620&amp;w=2" source="HP">SSRT100460</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130835366526620&amp;w=2" source="HP">HPSBUX02657</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129138831608422&amp;w=2" source="HP">HPSBUX02609</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129138831608422&amp;w=2" source="HP">HPSBUX02609</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Aug/msg00003.html" source="APPLE">APPLE-SA-2010-08-24-1</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=873" source="IDEFENSE">20100616 Samba 3.3.12 Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.14a" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.20" />
        <vers num="3.0.20a" />
        <vers num="3.0.20b" />
        <vers num="3.0.21" />
        <vers num="3.0.21a" />
        <vers num="3.0.21b" />
        <vers num="3.0.21c" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.23a" />
        <vers num="3.0.23b" />
        <vers num="3.0.23c" />
        <vers num="3.0.23d" />
        <vers num="3.0.24" />
        <vers num="3.0.25" edition="pre1" />
        <vers num="3.0.25" edition="pre2" />
        <vers num="3.0.25" edition="rc1" />
        <vers num="3.0.25" edition="rc2" />
        <vers num="3.0.25" edition="rc3" />
        <vers num="3.0.25a" />
        <vers num="3.0.25b" />
        <vers num="3.0.25c" />
        <vers num="3.0.26" />
        <vers num="3.0.26a" />
        <vers num="3.0.27" />
        <vers num="3.0.27a" />
        <vers num="3.0.28" />
        <vers num="3.0.28a" />
        <vers num="3.0.29" />
        <vers num="3.0.2a" />
        <vers num="3.0.3" />
        <vers num="3.0.30" />
        <vers num="3.0.31" />
        <vers num="3.0.32" />
        <vers num="3.0.33" />
        <vers num="3.0.34" />
        <vers num="3.0.35" />
        <vers num="3.0.36" />
        <vers num="3.0.37" />
        <vers num="3.0.4" edition="rc1" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.10" />
        <vers num="3.2.11" />
        <vers num="3.2.12" />
        <vers num="3.2.13" />
        <vers num="3.2.14" />
        <vers num="3.2.15" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.2.9" />
        <vers num="3.3" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.10" />
        <vers num="3.3.11" />
        <vers prev="1" num="3.3.12" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="3.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2065" published="2010-06-24" name="CVE-2010-2065" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file that triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=601274" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=601274</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/589565" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/tiff/+bug/589565</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0621" source="VUPEN">ADV-2011-0621</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0204" source="VUPEN">ADV-2011-0204</ref>
      <ref url="http://www.ubuntu.com/usn/USN-954-1" source="UBUNTU">USN-954-1</ref>
      <ref url="http://www.remotesensing.org/libtiff/v3.9.3.html" source="MISC">http://www.remotesensing.org/libtiff/v3.9.3.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:043" source="MANDRIVA">MDVSA-2011:043</ref>
      <ref url="http://secunia.com/advisories/40181" source="SECUNIA" adv="1">40181</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127731610612908&amp;w=2" source="MLIST">[oss-security] 20100623 CVE requests: LibTIFF</ref>
      <ref url="http://blogs.sun.com/security/entry/cve_2010_2065_cve_2010" source="CONFIRM">http://blogs.sun.com/security/entry/cve_2010_2065_cve_2010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" edition="beta18" />
        <vers num="3.4" edition="beta24" />
        <vers num="3.4" edition="beta28" />
        <vers num="3.4" edition="beta29" />
        <vers num="3.4" edition="beta31" />
        <vers num="3.4" edition="beta32" />
        <vers num="3.4" edition="beta34" />
        <vers num="3.4" edition="beta35" />
        <vers num="3.4" edition="beta36" />
        <vers num="3.4" edition="beta37" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" edition="beta" />
        <vers num="3.5.7" edition="alpha" />
        <vers num="3.5.7" edition="alpha2" />
        <vers num="3.5.7" edition="alpha3" />
        <vers num="3.5.7" edition="alpha4" />
        <vers num="3.5.7" edition="beta" />
        <vers num="3.6.0" edition="beta" />
        <vers num="3.6.0" edition="beta2" />
        <vers num="3.6.1" />
        <vers num="3.7.0" edition="alpha" />
        <vers num="3.7.0" edition="beta" />
        <vers num="3.7.0" edition="beta2" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.4" />
        <vers num="3.8.0" />
        <vers num="3.8.1" />
        <vers num="3.8.2" />
        <vers num="3.9" />
        <vers num="3.9.0" edition="beta" />
        <vers num="3.9.1" />
        <vers prev="1" num="3.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2066" published="2010-09-08" name="CVE-2010-2066" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=601006" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=601006</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1000-1" source="UBUNTU">USN-1000-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0610.html" source="REDHAT">RHSA-2010:0610</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/09/1" source="MLIST">[oss-security] 20100609 Re: CVE request - kernel: ext4: Make sure the MOVE_EXT ioctl can't overwrite append-only files</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/07/1" source="MLIST">[oss-security] 20100607 CVE request - kernel: ext4: Make sure the MOVE_EXT ioctl can't overwrite append-only files</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00000.html" source="SUSE">SUSE-SA:2010:033</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1f5a81e41f8b1a782c68d3843e9ec1bfaadf7d72" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1f5a81e41f8b1a782c68d3843e9ec1bfaadf7d72</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.13" />
        <vers num="2.6.31.14" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.11" />
        <vers num="2.6.32.12" />
        <vers num="2.6.32.13" />
        <vers num="2.6.32.14" />
        <vers num="2.6.32.15" />
        <vers num="2.6.32.16" />
        <vers num="2.6.32.17" />
        <vers num="2.6.32.18" />
        <vers num="2.6.32.19" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.20" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33" edition="rc7" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers num="2.6.33.3" />
        <vers num="2.6.33.4" />
        <vers num="2.6.33.5" />
        <vers num="2.6.33.6" />
        <vers num="2.6.33.7" />
        <vers num="2.6.34" />
        <vers num="2.6.34.1" />
        <vers num="2.6.34.2" />
        <vers num="2.6.34.3" />
        <vers num="2.6.34.4" />
        <vers num="2.6.34.5" />
        <vers prev="1" num="2.6.34.6" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2067" published="2010-06-24" name="CVE-2010-2067" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=599576" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=599576</ref>
      <ref url="http://www.ubuntu.com/usn/USN-954-1" source="UBUNTU">USN-954-1</ref>
      <ref url="http://www.remotesensing.org/libtiff/v3.9.4.html" source="CONFIRM">http://www.remotesensing.org/libtiff/v3.9.4.html</ref>
      <ref url="http://secunia.com/advisories/40241" source="SECUNIA" adv="1">40241</ref>
      <ref url="http://osvdb.org/65676" source="OSVDB">65676</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=127731610612908&amp;w=2" source="MLIST">[oss-security] 20100623 CVE requests: LibTIFF</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://bugzilla.maptools.org/show_bug.cgi?id=2212" source="CONFIRM">http://bugzilla.maptools.org/show_bug.cgi?id=2212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.4" edition="beta18" />
        <vers num="3.4" edition="beta24" />
        <vers num="3.4" edition="beta28" />
        <vers num="3.4" edition="beta29" />
        <vers num="3.4" edition="beta31" />
        <vers num="3.4" edition="beta32" />
        <vers num="3.4" edition="beta34" />
        <vers num="3.4" edition="beta35" />
        <vers num="3.4" edition="beta36" />
        <vers num="3.4" edition="beta37" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" edition="beta" />
        <vers num="3.5.7" edition="alpha" />
        <vers num="3.5.7" edition="alpha2" />
        <vers num="3.5.7" edition="alpha3" />
        <vers num="3.5.7" edition="alpha4" />
        <vers num="3.5.7" edition="beta" />
        <vers num="3.6.0" edition="beta" />
        <vers num="3.6.0" edition="beta2" />
        <vers num="3.6.1" />
        <vers num="3.7.0" edition="alpha" />
        <vers num="3.7.0" edition="beta" />
        <vers num="3.7.0" edition="beta2" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.7.4" />
        <vers num="3.8.0" />
        <vers num="3.8.1" />
        <vers num="3.8.2" />
        <vers num="3.9" />
        <vers num="3.9.0" edition="beta" />
        <vers num="3.9.1" />
        <vers prev="1" num="3.9.2" />
        <vers prev="1" num="3.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2068" published="2010-06-18" name="CVE-2010-2068" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://httpd.apache.org/security/vulnerabilities_22.html

'Only Windows, Netware and OS2 operating systems are affected.'</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1436" source="VUPEN" patch="1" adv="1">ADV-2010-1436</ref>
      <ref url="http://www.apache.org/dist/httpd/patches/apply_to_2.3.5/CVE-2010-2068-r953418.patch" source="CONFIRM" patch="1">http://www.apache.org/dist/httpd/patches/apply_to_2.3.5/CVE-2010-2068-r953418.patch</ref>
      <ref url="http://www.apache.org/dist/httpd/patches/apply_to_2.2.15/CVE-2010-2068-r953616.patch" source="CONFIRM" patch="1">http://www.apache.org/dist/httpd/patches/apply_to_2.2.15/CVE-2010-2068-r953616.patch</ref>
      <ref url="http://httpd.apache.org/security/vulnerabilities_22.html" source="CONFIRM" patch="1" adv="1">http://httpd.apache.org/security/vulnerabilities_22.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59413" source="XF">apache-modproxyhttp-timeout-info-disc(59413)</ref>
      <ref url="http://www.securityfocus.com/bid/40827" source="BID">40827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511809/100/0/threaded" source="BUGTRAQ">20100611 [advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0896.html" source="REDHAT">RHSA-2011:0896</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995" source="HP">SSRT100219</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995" source="HP">SSRT100219</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg1PM16366" source="AIXAPAR">PM16366</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=nas352ca0ac9460f9b8886257777005dd0e4" source="AIXAPAR">SI4053</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://securitytracker.com/id?1024096" source="SECTRACK">1024096</ref>
      <ref url="http://secunia.com/advisories/41722" source="SECUNIA">41722</ref>
      <ref url="http://secunia.com/advisories/41490" source="SECUNIA">41490</ref>
      <ref url="http://secunia.com/advisories/41480" source="SECUNIA">41480</ref>
      <ref url="http://secunia.com/advisories/40824" source="SECUNIA">40824</ref>
      <ref url="http://secunia.com/advisories/40206" source="SECUNIA" adv="1">40206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6931" source="OVAL">oval:org.mitre.oval:def:6931</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11491" source="OVAL">oval:org.mitre.oval:def:11491</ref>
      <ref url="http://marc.info/?l=apache-announce&amp;m=128009718610929&amp;w=2" source="MLIST">[apache-announce] 20100725 [ANNOUNCEMENT] Apache HTTP Server 2.2.16 Released</ref>
      <ref url="http://mail-archives.apache.org/mod_mbox/httpd-announce/201006.mbox/%3C4C12933D.4060400@apache.org%3E" source="MLIST" adv="1">[httpd-announce] 20100611 [advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2.10" />
        <vers num="2.2.11" />
        <vers num="2.2.12" />
        <vers num="2.2.13" />
        <vers num="2.2.14" />
        <vers num="2.2.15" />
        <vers num="2.2.9" />
        <vers num="2.3.4" edition="alpha" />
        <vers num="2.3.5" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2070" published="2010-06-16" name="CVE-2010-2070" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of service and "turn on BE by modifying the user mask of the PSR," as demonstrated via exploitation of CVE-2006-0742.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=586415" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=586415</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59373" source="XF">xen-faults-dos(59373)</ref>
      <ref url="http://xenbits.xensource.com/xen-4.0-testing.hg?rev/42caadb14edb" source="MISC">http://xenbits.xensource.com/xen-4.0-testing.hg?rev/42caadb14edb</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/40776" source="BID">40776</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0610.html" source="REDHAT">RHSA-2010:0610</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/10/2" source="MLIST">[oss-security] 20100611 CVE-2010-2070 kernel-xen: ia64-xen: unset be from the task psr</ref>
      <ref url="http://secunia.com/advisories/43315" source="SECUNIA">43315</ref>
      <ref url="http://osvdb.org/65541" source="OSVDB">65541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xensource" name="xen">
        <vers num="3.4.0" />
        <vers num="4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2071" published="2010-06-16" name="CVE-2010-2071" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lkml.org/lkml/2010/5/17/544" source="MLIST" patch="1">[linux-kernel] 20100518 [PATCH] btrfs: should add a permission check for setfacl</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=2f26afba" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=2f26afba</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/14/2" source="MLIST">[oss-security] 20100614 Re: CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/11/3" source="MLIST">[oss-security] 20100611 CVE request - kernel: btrfs: prevent users from setting ACLs on files they do not own</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" edition="-rc1" />
        <vers num="2.6.16.31" edition="-rc2" />
        <vers num="2.6.16.31" edition="-rc3" />
        <vers num="2.6.16.31" edition="-rc4" />
        <vers num="2.6.16.31" edition="-rc5" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.10" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.10" />
        <vers num="2.6.31.11" />
        <vers num="2.6.31.12" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers num="2.6.31.7" />
        <vers num="2.6.31.8" />
        <vers num="2.6.31.9" />
        <vers num="2.6.32" edition="git-6" />
        <vers num="2.6.32" edition="rc1" />
        <vers num="2.6.32" edition="rc3" />
        <vers num="2.6.32" edition="rc4" />
        <vers num="2.6.32" edition="rc5" />
        <vers num="2.6.32" edition="rc6" />
        <vers num="2.6.32" edition="rc7" />
        <vers num="2.6.32" edition="rc8" />
        <vers num="2.6.32.1" />
        <vers num="2.6.32.10" />
        <vers num="2.6.32.2" />
        <vers num="2.6.32.3" />
        <vers num="2.6.32.4" />
        <vers num="2.6.32.5" />
        <vers num="2.6.32.6" />
        <vers num="2.6.32.7" />
        <vers num="2.6.32.8" />
        <vers num="2.6.32.9" />
        <vers num="2.6.33" edition="rc1" />
        <vers num="2.6.33" edition="rc2" />
        <vers num="2.6.33" edition="rc3" />
        <vers num="2.6.33" edition="rc4" />
        <vers num="2.6.33" edition="rc5" />
        <vers num="2.6.33" edition="rc6" />
        <vers num="2.6.33" edition="rc7" />
        <vers num="2.6.33" edition="rc8" />
        <vers num="2.6.33.1" />
        <vers num="2.6.33.2" />
        <vers num="2.6.33.3" />
        <vers num="2.6.33.4" />
        <vers num="2.6.33.5" />
        <vers prev="1" num="2.6.34" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2072" published="2010-06-16" name="CVE-2010-2072" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59429" source="XF">pyftpd-logfile-symlink(59429)</ref>
      <ref url="http://www.securityfocus.com/bid/40842" source="BID">40842</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/13/1" source="MLIST">[oss-security] 20100613 CVE request - pyftpd insecure usage of temporary directory</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=585773" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=585773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radovan_garabik" name="pyftpd">
        <vers num="0.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2073" published="2010-06-16" name="CVE-2010-2073" modified="2010-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/59431" source="XF">pyftpd-default-account(59431)</ref>
      <ref url="http://www.securityfocus.com/bid/40839" source="BID">40839</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/13/2" source="MLIST">[oss-security] 20100613 CVE request - pyftpd default username and password vulnerability</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=585776" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=585776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="radovan_garabik" name="pyftpd">
        <vers num="0.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2074" published="2010-06-16" name="CVE-2010-2074" modified="2010-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1928" source="VUPEN">ADV-2010-1928</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1879" source="VUPEN">ADV-2010-1879</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1467" source="VUPEN" adv="1">ADV-2010-1467</ref>
      <ref url="http://www.securitytracker.com/id?1024252" source="SECTRACK">1024252</ref>
      <ref url="http://www.securityfocus.com/bid/40837" source="BID">40837</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0565.html" source="REDHAT">RHSA-2010:0565</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/14/4" source="MLIST">[oss-security] 20100614 CVE Request: w3m does not check null bytes CN/subjAltName</ref>
      <ref url="http://secunia.com/advisories/40733" source="SECUNIA">40733</ref>
      <ref url="http://secunia.com/advisories/40134" source="SECUNIA" adv="1">40134</ref>
      <ref url="http://osvdb.org/65538" source="OSVDB">65538</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html" source="SUSE">SUSE-SR:2010:014</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044401.html" source="FEDORA">FEDORA-2010-10369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3m" name="w3m">
        <vers num="0.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2075" published="2010-06-15" name="CVE-2010-2075" modified="2010-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.</descript>
      <descript source="nvd">Per: http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt

'Official precompiled Windows binaries (SSL and non-ssl) are NOT affected.

CVS is also not affected.

3.2.8 and any earlier versions are not affected.

Any Unreal3.2.8.1.tar.gz downloaded BEFORE November 10 2009 should be safe, but you should really double-check, see next.'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1437" source="VUPEN" adv="1">ADV-2010-1437</ref>
      <ref url="http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt" source="CONFIRM" adv="1">http://www.unrealircd.com/txt/unrealsecadvisory.20100612.txt</ref>
      <ref url="http://www.securityfocus.com/bid/40820" source="BID">40820</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2010/06/14/11" source="MLIST">[oss-security] 20100614 Re: CVE request: UnrealIRCd 3.2.8.1 source code contained a backdoor allowing for remote command execution</ref>
      <ref url="http://www.exploit-db.com/exploits/13853" source="EXPLOIT-DB">13853</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201006-21.xml" source="GENTOO">GLSA-201006-21</ref>
      <ref url="http://secunia.com/advisories/40169" source="SECUNIA" adv="1">40169</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Jun/284" source="FULLDISC">20100612 Re: Fw: [irc-security] UnrealIRCd 3.2.8.1 backdoored on official ftp and site</ref>
      <ref url="http://seclists.org/fulldisclosure/2010/Jun/277" source="FULLDISC">20100612 Fw: [irc-security] UnrealIRCd 3.2.8.1 backdoored on official ftp and site</ref>
      <ref url="http://osvdb.org/65445" source="OSVDB">65445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unrealircd" name="unrealircd">
        <vers num="3.2.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2076" published="2010-08-19" name="CVE-2010-2076" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.apache.org/jira/browse/GERONIMO-5383" source="CONFIRM">https://issues.apache.org/jira/browse/GERONIMO-5383</ref>
      <ref url="http://www.securityfocus.com/bid/42492" source="BID">42492</ref>
      <ref url="http://www.listware.net/201006/cxf-users/60160-important-apache-cxf-security-advisory-cve-2010-2076.html" source="MLIST">[cxf-users] 20100616 Important - Apache CXF security advisory CVE-2010-2076</ref>
      <ref url="http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf" source="CONFIRM" adv="1">http://svn.apache.org/repos/asf/cxf/trunk/security/CVE-2010-2076.pdf</ref>
      <ref url="http://secunia.com/advisories/41025" source="SECUNIA" adv="1">41025</ref>
      <ref url="http://secunia.com/advisories/41016" source="SECUNIA" adv="1">41016</ref>
      <ref url="http://secunia.com/advisories/40969" source="SECUNIA" adv="1">40969</ref>
      <ref url="http://geronimo.apache.org/22x-security-report.html" source="CONFIRM" adv="1">http://geronimo.apache.org/22x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html" source="CONFIRM" adv="1">http://geronimo.apache.org/21x-security-report.html</ref>
      <ref url="http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html" source="CONFIRM">http://geronimo.apache.org/2010/07/21/apache-geronimo-v216-released.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="cxf">
        <vers num="2.0" edition="m1" />
        <vers num="2.0" edition="rc" />
        <vers num="2.0.1" />
        <vers num="2.0.10" />
        <vers num="2.0.11" />
        <vers num="2.0.12" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.0.7" />
        <vers num="2.0.8" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.9" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2010-2077" reject="1" published="2010-05-25" name="CVE-2010-2077" modified="2010-05-25">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2010-1640.  Reason: This candidate is a duplicate of CVE-2010-1640.  Notes: All CVE users should reference CVE-2010-1640 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2078" published="2010-05-25" name="CVE-2010-2078" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58734" source="XF">datatrack-unicode-info-disc(58734)</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html" source="MISC">http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magnoware" name="datatrack_system">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2079" published="2010-05-25" name="CVE-2010-2079" modified="2010-05-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions, and read arbitrary files, via a trailing backslash in a URI, as demonstrated by (1) web.config\ and (2) .ascx\ files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58735" source="XF">datatrack-backslash-info-disc(58735)</ref>
      <ref url="http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt" source="MISC">http://packetstormsecurity.org/1005-exploits/datatrackserver35-xss.txt</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html" source="MISC">http://cross-site-scripting.blogspot.com/2010/05/datatrack-system-35-persistent-xss.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magnoware" name="datatrack_system">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2080" published="2010-09-20" name="CVE-2010-2080" modified="2011-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/61868" source="XF">otrs-unspecified-xss(61868)</ref>
      <ref url="http://www.securityfocus.com/bid/43264" source="BID">43264</ref>
      <ref url="http://security-tracker.debian.org/tracker/CVE-2010-2080" source="CONFIRM">http://security-tracker.debian.org/tracker/CVE-2010-2080</ref>
      <ref url="http://secunia.com/advisories/41381" source="SECUNIA" adv="1">41381</ref>
      <ref url="http://otrs.org/advisory/OSA-2010-02-en/" source="CONFIRM" adv="1">http://otrs.org/advisory/OSA-2010-02-en/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="otrs" name="otrs">
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2082" published="2010-05-26" name="CVE-2010-2082" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, which makes it easier for remote attackers to obtain privileged access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0322.html" source="FULLDISC">20100524 Scientific Atlanta DPC2100 WebSTAR Cable Modem vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="scientific_atlanta_webstar_dpc2100r2">
        <vers num="2.0.2r1256-060303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2083" published="2010-05-26" name="CVE-2010-2083" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Dynamics GP has a default value of ACCESS for the system password, which might make it easier for remote authenticated users to bypass intended access restrictions via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.christopherkois.com/?p=448" source="MISC">http://www.christopherkois.com/?p=448</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="dynamics_gp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2084" published="2010-05-27" name="CVE-2010-2084" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/03/30/configuration-is-half-the-battle-asp-net-and-cross-site-scripting.aspx" source="MISC">http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/03/30/configuration-is-half-the-battle-asp-net-and-cross-site-scripting.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2085" published="2010-05-27" name="CVE-2010-2085" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers prev="1" num="1.0" edition="beta2" />
        <vers prev="1" num="1.0" edition="gold" />
        <vers prev="1" num="1.0" edition="sp1" />
        <vers prev="1" num="1.0" edition="sp2" />
        <vers prev="1" num="1.0" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2086" published="2010-05-27" name="CVE-2010-2086" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="myfaces">
        <vers num="1.1.7" />
        <vers num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2087" published="2010-05-27" name="CVE-2010-2087" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="mojarra">
        <vers num="1.2_14" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2088" published="2010-05-27" name="CVE-2010-2088" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="asp.net">
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2089" published="2010-05-27" name="CVE-2010-2089" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.python.org/issue7673" source="CONFIRM" patch="1">http://bugs.python.org/issue7673</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=598197" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=598197</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0122" source="VUPEN">ADV-2011-0122</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1448" source="VUPEN">ADV-2010-1448</ref>
      <ref url="http://www.securityfocus.com/bid/40863" source="BID">40863</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0027.html" source="REDHAT">RHSA-2011:0027</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42888" source="SECUNIA">42888</ref>
      <ref url="http://secunia.com/advisories/40194" source="SECUNIA">40194</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html" source="SUSE">SUSE-SR:2010:024</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042751.html" source="FEDORA">FEDORA-2010-9652</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="python" name="python">
        <vers num="2.7" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2090" published="2010-05-27" name="CVE-2010-2090" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58874" source="XF">csa-appc-dos(58874)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1244" source="VUPEN" adv="1">ADV-2010-1244</ref>
      <ref url="http://www.securityfocus.com/bid/40372" source="BID">40372</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24013012" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg24013012</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1JR36026" source="AIXAPAR">JR36026</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68810" source="AIXAPAR">IZ68810</ref>
      <ref url="http://secunia.com/advisories/39909" source="SECUNIA" adv="1">39909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="communications_server">
        <vers num="6.1.3" />
        <vers num="6.3.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2091" published="2010-05-27" name="CVE-2010-2091" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58835" source="XF">ms-owa-id-xss(58835)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511448/100/0/threaded" source="BUGTRAQ">20100525 Re: Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511416/100/0/threaded" source="BUGTRAQ">20100521 Re: Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511401/100/0/threaded" source="BUGTRAQ">20100520 Microsoft Outlook Web Access (OWA) v8.2.254.0 "id" parameter Information Disclosure Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/12728" source="EXPLOIT-DB">12728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2007" edition="sp2_update_rollup_4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2092" published="2010-05-27" name="CVE-2010-2092" modified="2010-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0635.html" source="REDHAT">RHSA-2010:0635</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2060" source="DEBIAN">DSA-2060</ref>
      <ref url="http://www.cacti.net/changelog.php" source="CONFIRM">http://www.cacti.net/changelog.php</ref>
      <ref url="http://secunia.com/advisories/41041" source="SECUNIA">41041</ref>
      <ref url="http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cacti" name="cacti">
        <vers num="0.5" edition="-" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.8a" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.2a" />
        <vers num="0.8.3" />
        <vers num="0.8.3a" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.5a" />
        <vers num="0.8.6" />
        <vers num="0.8.6a" />
        <vers num="0.8.6b" />
        <vers num="0.8.6c" />
        <vers num="0.8.6d" />
        <vers num="0.8.6f" />
        <vers num="0.8.6g" />
        <vers num="0.8.6h" />
        <vers num="0.8.6i" />
        <vers num="0.8.6j" />
        <vers num="0.8.6k" />
        <vers num="0.8.7" />
        <vers num="0.8.7a" />
        <vers num="0.8.7b" />
        <vers num="0.8.7c" />
        <vers num="0.8.7d" />
        <vers prev="1" num="0.8.7e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2093" published="2010-05-27" name="CVE-2010-2093" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the request shutdown functionality in PHP 5.2 before 5.2.13 and 5.3 before 5.3.2 allows context-dependent attackers to cause a denial of service (crash) via a stream context structure that is freed before destruction occurs.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/12/mops-2010-022-php-stream-context-use-after-free-on-request-shutdown-vulnerability/index.html" source="MISC" adv="1">http://php-security.org/2010/05/12/mops-2010-022-php-stream-context-use-after-free-on-request-shutdown-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2094" published="2010-05-27" name="CVE-2010-2094" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0068" source="VUPEN">ADV-2011-0068</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:004" source="MANDRIVA">MDVSA-2011:004</ref>
      <ref url="http://php-security.org/2010/05/14/mops-2010-028-php-phar_wrapper_open_url-format-string-vulnerabilities/index.html" source="MISC">http://php-security.org/2010/05/14/mops-2010-028-php-phar_wrapper_open_url-format-string-vulnerabilities/index.html</ref>
      <ref url="http://php-security.org/2010/05/14/mops-2010-027-php-phar_parse_url-format-string-vulnerabilities/index.html" source="MISC">http://php-security.org/2010/05/14/mops-2010-027-php-phar_parse_url-format-string-vulnerabilities/index.html</ref>
      <ref url="http://php-security.org/2010/05/14/mops-2010-026-php-phar_wrapper_unlink-format-string-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/14/mops-2010-026-php-phar_wrapper_unlink-format-string-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/14/mops-2010-025-php-phar_wrapper_open_dir-format-string-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/14/mops-2010-025-php-phar_wrapper_open_dir-format-string-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/14/mops-2010-024-php-phar_stream_flush-format-string-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.3.0" />
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2095" published="2010-05-27" name="CVE-2010-2095" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/15/mops-2010-029-cmsqlite-c-parameter-sql-injection-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/15/mops-2010-029-cmsqlite-c-parameter-sql-injection-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsqlite" name="cmsqlite">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2096" published="2010-05-27" name="CVE-2010-2096" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/15/mops-2010-030-cmsqlite-mod-parameter-local-file-inclusion-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/15/mops-2010-030-cmsqlite-mod-parameter-local-file-inclusion-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmsqlite" name="cmsqlite">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2097" published="2010-05-27" name="CVE-2010-2097" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/18/mops-2010-034-php-iconv_mime_encode-interruption-information-leak-vulnerability/index.html" source="MISC" adv="1">http://php-security.org/2010/05/18/mops-2010-034-php-iconv_mime_encode-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/18/mops-2010-033-php-iconv_substr-interruption-information-leak-vulnerability/index.html" source="MISC" adv="1">http://php-security.org/2010/05/18/mops-2010-033-php-iconv_substr-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/18/mops-2010-032-php-iconv_mime_decode-interruption-information-leak-vulnerability/index.html" source="MISC" adv="1">http://php-security.org/2010/05/18/mops-2010-032-php-iconv_mime_decode-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2098" published="2010-05-27" name="CVE-2010-2098" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks via the loginname parameter.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/184.html

'CWE-184: Incomplete Blacklist'</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11538&amp;r2=11541" source="CONFIRM">http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11538&amp;r2=11541</ref>
      <ref url="http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11521&amp;r2=11538" source="CONFIRM">http://e107.svn.sourceforge.net/viewvc/e107/trunk/e107_0.7/usersettings.php?r1=11521&amp;r2=11538</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.547" edition="beta" />
        <vers num="0.548" edition="beta" />
        <vers num="0.549" edition="beta" />
        <vers num="0.551" edition="beta" />
        <vers num="0.552" edition="beta" />
        <vers num="0.553" edition="beta" />
        <vers num="0.554" edition="beta" />
        <vers num="0.555" edition="beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="0.6171" />
        <vers num="0.6172" />
        <vers num="0.6173" />
        <vers num="0.6174" />
        <vers num="0.6175" />
        <vers num="0.6_10" />
        <vers num="0.6_11" />
        <vers num="0.6_12" />
        <vers num="0.6_13" />
        <vers num="0.6_14" />
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
        <vers num="0.7" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.12" />
        <vers num="0.7.13" />
        <vers num="0.7.14" />
        <vers num="0.7.15" />
        <vers num="0.7.16" />
        <vers num="0.7.17" />
        <vers num="0.7.18" />
        <vers num="0.7.19" />
        <vers num="0.7.2" />
        <vers prev="1" num="0.7.20" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2099" published="2010-05-27" name="CVE-2010-2099" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/40252" source="BID">40252</ref>
      <ref url="http://php-security.org/2010/05/19/mops-2010-035-e107-bbcode-remote-php-code-execution-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/19/mops-2010-035-e107-bbcode-remote-php-code-execution-vulnerability/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.547" edition="beta" />
        <vers num="0.548" edition="beta" />
        <vers num="0.549" edition="beta" />
        <vers num="0.551" edition="beta" />
        <vers num="0.552" edition="beta" />
        <vers num="0.553" edition="beta" />
        <vers num="0.554" edition="beta" />
        <vers num="0.555" edition="beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="0.6171" />
        <vers num="0.6172" />
        <vers num="0.6173" />
        <vers num="0.6174" />
        <vers num="0.6175" />
        <vers num="0.6_10" />
        <vers num="0.6_11" />
        <vers num="0.6_12" />
        <vers num="0.6_13" />
        <vers num="0.6_14" />
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
        <vers num="0.7" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.12" />
        <vers num="0.7.13" />
        <vers num="0.7.14" />
        <vers num="0.7.15" />
        <vers num="0.7.16" />
        <vers num="0.7.17" />
        <vers num="0.7.18" />
        <vers num="0.7.19" />
        <vers num="0.7.2" />
        <vers prev="1" num="0.7.20" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2100" published="2010-05-27" name="CVE-2010-2100" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) http_build_query, (5) strpbrk, and (6) strtr functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/21/mops-2010-040-php-strtr-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/21/mops-2010-040-php-strtr-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/21/mops-2010-039-php-strpbrk-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/21/mops-2010-039-php-strpbrk-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/21/mops-2010-038-php-http_build_query-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/21/mops-2010-038-php-http_build_query-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/21/mops-2010-037-php-str_getcsv-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/21/mops-2010-037-php-str_getcsv-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/21/mops-2010-036-php-htmlentities-and-htmlspecialchars-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/21/mops-2010-036-php-htmlentities-and-htmlspecialchars-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2101" published="2010-05-27" name="CVE-2010-2101" modified="2010-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://php-security.org/2010/05/26/mops-2010-046-php-str_pad-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-046-php-str_pad-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/26/mops-2010-045-php-str_word_count-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-045-php-str_word_count-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/26/mops-2010-044-php-wordwrap-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-044-php-wordwrap-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/26/mops-2010-043-php-strtok-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-043-php-strtok-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/26/mops-2010-042-php-setcookie-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-042-php-setcookie-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://php-security.org/2010/05/26/mops-2010-041-php-strip_tags-interruption-information-leak-vulnerability/index.html" source="MISC">http://php-security.org/2010/05/26/mops-2010-041-php-strip_tags-interruption-information-leak-vulnerability/index.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.html" source="SUSE">SUSE-SR:2010:018</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html" source="SUSE">SUSE-SR:2010:017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.10" />
        <vers num="5.2.11" />
        <vers num="5.2.12" />
        <vers num="5.2.13" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="5.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2102" published="2010-05-27" name="CVE-2010-2102" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58892" source="XF">webby-get-bo(58892)</ref>
      <ref url="http://www.securityfocus.com/bid/40353" source="BID">40353</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511428/100/0/threaded" source="BUGTRAQ">20100525 Webby Webserver v1.01 - Buffer overflow vulnerability with overwritten structured exception handler (SEH)</ref>
      <ref url="http://www.exploit-db.com/exploits/12740" source="EXPLOIT-DB">12740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="timo_gaik" name="webby_webserver">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2103" published="2010-05-27" name="CVE-2010-2103" modified="2010-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58790" source="XF">axis2-modules-xss(58790)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1215" source="VUPEN" adv="1">ADV-2010-1215</ref>
      <ref url="http://www.securityfocus.com/bid/40327" source="BID">40327</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511404/100/0/threaded" source="BUGTRAQ">20100521 PR10-03: Authenticated Cross-Site Scripting (XSS) within the Apache Axis2 administration console</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-03" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-03</ref>
      <ref url="http://www.exploit-db.com/exploits/12689" source="EXPLOIT-DB">12689</ref>
      <ref url="http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf" source="MISC">http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf</ref>
      <ref url="http://secunia.com/advisories/39906" source="SECUNIA" adv="1">39906</ref>
      <ref url="http://osvdb.org/64844" source="OSVDB">64844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="axis2">
        <vers num="1.4.1" />
        <vers num="1.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2104" published="2010-05-27" name="CVE-2010-2104" modified="2010-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/511348/100/100/threaded" source="BUGTRAQ">20100519 Secunia Research: Orbit Downloader metalink "name" Directory Traversal</ref>
      <ref url="http://secunia.com/secunia_research/2010-73/" source="MISC" adv="1">http://secunia.com/secunia_research/2010-73/</ref>
      <ref url="http://secunia.com/advisories/39527" source="SECUNIA" adv="1">39527</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbitdownloader" name="orbit_downloader">
        <vers num="3.0.0.4" />
        <vers num="3.0.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2105" published="2010-05-28" name="CVE-2010-2105" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12113" source="OVAL">oval:org.mitre.oval:def:12113</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=7713" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=7713</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2106" published="2010-05-28" name="CVE-2010-2106" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11644" source="OVAL">oval:org.mitre.oval:def:11644</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=16535" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=16535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2107" published="2010-05-28" name="CVE-2010-2107" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 5.0.375.55 allows attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the Safe Browsing functionality.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12128" source="OVAL">oval:org.mitre.oval:def:12128</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=30079" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=30079</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2108" published="2010-05-28" name="CVE-2010-2108" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the whitelist-mode plugin blocker via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12126" source="OVAL">oval:org.mitre.oval:def:12126</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=39740" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=39740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2109" published="2010-05-28" name="CVE-2010-2109" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12083" source="OVAL">oval:org.mitre.oval:def:12083</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=41469" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=41469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2110" published="2010-05-28" name="CVE-2010-2110" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12123" source="OVAL">oval:org.mitre.oval:def:12123</ref>
      <ref url="http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2010/05/stable-channel-update.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=42228" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=42228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="1.0.154.64" />
        <vers num="1.0.154.65" />
        <vers num="2.0.169.0" />
        <vers num="2.0.169.1" />
        <vers num="2.0.170.0" />
        <vers num="2.0.172.2" />
        <vers num="2.0.172.27" />
        <vers num="2.0.172.28" />
        <vers num="2.0.172.30" />
        <vers num="2.0.172.33" />
        <vers num="2.0.172.37" />
        <vers num="2.0.172.38" />
        <vers num="2.0.172.8" />
        <vers num="3.0.182.2" />
        <vers num="3.0.190.2" />
        <vers num="3.0.195.25" />
        <vers num="3.0.195.27" />
        <vers num="3.0.195.33" />
        <vers num="3.0.195.36" />
        <vers num="3.0.195.37" />
        <vers num="3.0.195.38" />
        <vers num="4.0.212.0" />
        <vers num="4.0.212.1" />
        <vers num="4.0.221.8" />
        <vers num="4.0.222.0" />
        <vers num="4.0.222.1" />
        <vers num="4.0.222.12" />
        <vers num="4.0.222.5" />
        <vers num="4.0.223.0" />
        <vers num="4.0.223.1" />
        <vers num="4.0.223.2" />
        <vers num="4.0.223.4" />
        <vers num="4.0.223.5" />
        <vers num="4.0.223.7" />
        <vers num="4.0.223.8" />
        <vers num="4.0.223.9" />
        <vers num="4.0.224.0" />
        <vers num="4.0.229.1" />
        <vers num="4.0.235.0" />
        <vers num="4.0.236.0" />
        <vers num="4.0.237.0" />
        <vers num="4.0.237.1" />
        <vers num="4.0.239.0" />
        <vers num="4.0.240.0" />
        <vers num="4.0.241.0" />
        <vers num="4.0.242.0" />
        <vers num="4.0.243.0" />
        <vers num="4.0.244.0" />
        <vers num="4.0.245.0" />
        <vers num="4.0.245.1" />
        <vers num="4.0.246.0" />
        <vers num="4.0.247.0" />
        <vers num="4.0.248.0" />
        <vers num="4.0.249.0" />
        <vers num="4.0.249.1" />
        <vers num="4.0.249.10" />
        <vers num="4.0.249.11" />
        <vers num="4.0.249.12" />
        <vers num="4.0.249.14" />
        <vers num="4.0.249.16" />
        <vers num="4.0.249.17" />
        <vers num="4.0.249.18" />
        <vers num="4.0.249.19" />
        <vers num="4.0.249.2" />
        <vers num="4.0.249.20" />
        <vers num="4.0.249.21" />
        <vers num="4.0.249.22" />
        <vers num="4.0.249.23" />
        <vers num="4.0.249.24" />
        <vers num="4.0.249.25" />
        <vers num="4.0.249.26" />
        <vers num="4.0.249.27" />
        <vers num="4.0.249.28" />
        <vers num="4.0.249.29" />
        <vers num="4.0.249.3" />
        <vers num="4.0.249.30" />
        <vers num="4.0.249.31" />
        <vers num="4.0.249.32" />
        <vers num="4.0.249.33" />
        <vers num="4.0.249.34" />
        <vers num="4.0.249.35" />
        <vers num="4.0.249.36" />
        <vers num="4.0.249.37" />
        <vers num="4.0.249.38" />
        <vers num="4.0.249.39" />
        <vers num="4.0.249.4" />
        <vers num="4.0.249.40" />
        <vers num="4.0.249.41" />
        <vers num="4.0.249.42" />
        <vers num="4.0.249.43" />
        <vers num="4.0.249.44" />
        <vers num="4.0.249.45" />
        <vers num="4.0.249.46" />
        <vers num="4.0.249.47" />
        <vers num="4.0.249.48" />
        <vers num="4.0.249.49" />
        <vers num="4.0.249.5" />
        <vers num="4.0.249.50" />
        <vers num="4.0.249.51" />
        <vers num="4.0.249.52" />
        <vers num="4.0.249.53" />
        <vers num="4.0.249.54" />
        <vers num="4.0.249.55" />
        <vers num="4.0.249.56" />
        <vers num="4.0.249.57" />
        <vers num="4.0.249.58" />
        <vers num="4.0.249.59" />
        <vers num="4.0.249.6" />
        <vers num="4.0.249.60" />
        <vers num="4.0.249.61" />
        <vers num="4.0.249.62" />
        <vers num="4.0.249.63" />
        <vers num="4.0.249.64" />
        <vers num="4.0.249.65" />
        <vers num="4.0.249.66" />
        <vers num="4.0.249.67" />
        <vers num="4.0.249.68" />
        <vers num="4.0.249.69" />
        <vers num="4.0.249.7" />
        <vers num="4.0.249.70" />
        <vers num="4.0.249.71" />
        <vers num="4.0.249.72" />
        <vers num="4.0.249.73" />
        <vers num="4.0.249.74" />
        <vers num="4.0.249.75" />
        <vers num="4.0.249.76" />
        <vers num="4.0.249.77" />
        <vers num="4.0.249.78" edition="beta" />
        <vers num="4.0.249.79" />
        <vers num="4.0.249.8" />
        <vers num="4.0.249.80" />
        <vers num="4.0.249.81" />
        <vers num="4.0.249.82" />
        <vers num="4.0.249.89" />
        <vers num="4.0.249.9" />
        <vers num="4.0.250.0" />
        <vers num="4.0.250.2" />
        <vers num="4.0.251.0" />
        <vers num="4.0.252.0" />
        <vers num="4.0.254.0" />
        <vers num="4.0.255.0" />
        <vers num="4.0.256.0" />
        <vers num="4.0.257.0" />
        <vers num="4.0.258.0" />
        <vers num="4.0.259.0" />
        <vers num="4.0.260.0" />
        <vers num="4.0.261.0" />
        <vers num="4.0.262.0" />
        <vers num="4.0.263.0" />
        <vers num="4.0.264.0" />
        <vers num="4.0.265.0" />
        <vers num="4.0.266.0" />
        <vers num="4.0.267.0" />
        <vers num="4.0.268.0" />
        <vers num="4.0.269.0" />
        <vers num="4.0.271.0" />
        <vers num="4.0.272.0" />
        <vers num="4.0.275.0" />
        <vers num="4.0.275.1" />
        <vers num="4.0.276.0" />
        <vers num="4.0.277.0" />
        <vers num="4.0.278.0" />
        <vers num="4.0.286.0" />
        <vers num="4.0.287.0" />
        <vers num="4.0.288.0" />
        <vers num="4.0.288.1" />
        <vers num="4.0.289.0" />
        <vers num="4.0.290.0" />
        <vers num="4.0.292.0" />
        <vers num="4.0.294.0" />
        <vers num="4.0.295.0" />
        <vers num="4.0.296.0" />
        <vers num="4.0.299.0" />
        <vers num="4.0.300.0" />
        <vers num="4.0.301.0" />
        <vers num="4.0.302.0" />
        <vers num="4.0.302.1" />
        <vers num="4.0.302.2" />
        <vers num="4.0.302.3" />
        <vers num="4.0.303.0" />
        <vers num="4.0.304.0" />
        <vers num="4.0.305.0" />
        <vers num="4.1" edition="beta" />
        <vers num="4.1.249.0" />
        <vers num="4.1.249.1001" />
        <vers num="4.1.249.1004" />
        <vers num="4.1.249.1006" />
        <vers num="4.1.249.1007" />
        <vers num="4.1.249.1008" />
        <vers num="4.1.249.1009" />
        <vers num="4.1.249.1010" />
        <vers num="4.1.249.1011" />
        <vers num="4.1.249.1012" />
        <vers num="4.1.249.1013" />
        <vers num="4.1.249.1014" />
        <vers num="4.1.249.1015" />
        <vers num="4.1.249.1016" />
        <vers num="4.1.249.1017" />
        <vers num="4.1.249.1018" />
        <vers num="4.1.249.1019" />
        <vers num="4.1.249.1020" />
        <vers num="4.1.249.1021" />
        <vers num="4.1.249.1022" />
        <vers num="4.1.249.1023" />
        <vers num="4.1.249.1024" />
        <vers num="4.1.249.1025" />
        <vers num="4.1.249.1026" />
        <vers num="4.1.249.1027" />
        <vers num="4.1.249.1028" />
        <vers num="4.1.249.1029" />
        <vers num="4.1.249.1030" />
        <vers num="4.1.249.1031" />
        <vers num="4.1.249.1032" />
        <vers num="4.1.249.1033" />
        <vers num="4.1.249.1034" />
        <vers num="4.1.249.1035" />
        <vers num="4.1.249.1036" />
        <vers num="4.1.249.1037" />
        <vers num="4.1.249.1038" />
        <vers num="4.1.249.1039" />
        <vers num="4.1.249.1040" />
        <vers num="4.1.249.1041" />
        <vers num="4.1.249.1042" />
        <vers num="4.1.249.1043" />
        <vers num="4.1.249.1044" />
        <vers num="4.1.249.1045" />
        <vers num="4.1.249.1046" />
        <vers num="4.1.249.1047" />
        <vers num="4.1.249.1048" />
        <vers num="4.1.249.1049" />
        <vers num="4.1.249.1050" />
        <vers num="4.1.249.1051" />
        <vers num="4.1.249.1052" />
        <vers num="4.1.249.1053" />
        <vers num="4.1.249.1054" />
        <vers num="4.1.249.1055" />
        <vers num="4.1.249.1056" />
        <vers num="4.1.249.1057" />
        <vers num="4.1.249.1058" />
        <vers num="4.1.249.1059" />
        <vers num="4.1.249.1060" />
        <vers num="4.1.249.1061" />
        <vers num="4.1.249.1062" />
        <vers num="4.1.249.1063" />
        <vers num="4.1.249.1064" />
        <vers num="5.0.306.0" />
        <vers num="5.0.306.1" />
        <vers num="5.0.307.1" />
        <vers num="5.0.307.10" />
        <vers num="5.0.307.11" />
        <vers num="5.0.307.3" />
        <vers num="5.0.307.4" />
        <vers num="5.0.307.5" />
        <vers num="5.0.307.6" />
        <vers num="5.0.307.7" />
        <vers num="5.0.307.8" />
        <vers num="5.0.307.9" />
        <vers num="5.0.308.0" />
        <vers num="5.0.309.0" />
        <vers num="5.0.313.0" />
        <vers num="5.0.314.0" />
        <vers num="5.0.314.1" />
        <vers num="5.0.315.0" />
        <vers num="5.0.316.0" />
        <vers num="5.0.317.0" />
        <vers num="5.0.317.1" />
        <vers num="5.0.317.2" />
        <vers num="5.0.318.0" />
        <vers num="5.0.319.0" />
        <vers num="5.0.320.0" />
        <vers num="5.0.321.0" />
        <vers num="5.0.322.0" />
        <vers num="5.0.322.1" />
        <vers num="5.0.322.2" />
        <vers num="5.0.323.0" />
        <vers num="5.0.324.0" />
        <vers num="5.0.325.0" />
        <vers num="5.0.326.0" />
        <vers num="5.0.327.0" />
        <vers num="5.0.328.0" />
        <vers num="5.0.329.0" />
        <vers num="5.0.330.0" />
        <vers num="5.0.332.0" />
        <vers num="5.0.333.0" />
        <vers num="5.0.334.0" />
        <vers num="5.0.335.0" />
        <vers num="5.0.335.1" />
        <vers num="5.0.335.2" />
        <vers num="5.0.335.3" />
        <vers num="5.0.335.4" />
        <vers num="5.0.336.0" />
        <vers num="5.0.337.0" />
        <vers num="5.0.338.0" />
        <vers num="5.0.339.0" />
        <vers num="5.0.340.0" />
        <vers num="5.0.341.0" />
        <vers num="5.0.342.0" />
        <vers num="5.0.342.1" />
        <vers num="5.0.342.2" />
        <vers num="5.0.342.3" />
        <vers num="5.0.342.4" />
        <vers num="5.0.342.5" />
        <vers num="5.0.342.6" />
        <vers num="5.0.342.7" edition="beta" />
        <vers num="5.0.342.7" edition="beta:mac" />
        <vers num="5.0.342.8" edition="beta" />
        <vers num="5.0.342.8" edition="beta:windows" />
        <vers num="5.0.342.9" />
        <vers num="5.0.343.0" />
        <vers num="5.0.344.0" />
        <vers num="5.0.345.0" />
        <vers num="5.0.346.0" />
        <vers num="5.0.347.0" />
        <vers num="5.0.348.0" />
        <vers num="5.0.349.0" />
        <vers num="5.0.350.0" />
        <vers num="5.0.350.1" />
        <vers num="5.0.351.0" />
        <vers num="5.0.353.0" />
        <vers num="5.0.354.0" />
        <vers num="5.0.354.1" />
        <vers num="5.0.355.0" />
        <vers num="5.0.356.0" />
        <vers num="5.0.356.1" />
        <vers num="5.0.356.2" />
        <vers num="5.0.357.0" />
        <vers num="5.0.358.0" />
        <vers num="5.0.359.0" />
        <vers num="5.0.360.0" />
        <vers num="5.0.360.3" />
        <vers num="5.0.360.4" />
        <vers num="5.0.360.5" />
        <vers num="5.0.361.0" />
        <vers num="5.0.362.0" />
        <vers num="5.0.363.0" />
        <vers num="5.0.364.0" />
        <vers num="5.0.365.0" />
        <vers num="5.0.366.0" />
        <vers num="5.0.366.1" />
        <vers num="5.0.366.2" />
        <vers num="5.0.366.3" />
        <vers num="5.0.366.4" />
        <vers num="5.0.367.0" />
        <vers num="5.0.368.0" />
        <vers num="5.0.369.0" />
        <vers num="5.0.373.0" />
        <vers num="5.0.374.0" />
        <vers num="5.0.375.0" />
        <vers num="5.0.375.1" />
        <vers num="5.0.375.10" />
        <vers num="5.0.375.11" />
        <vers num="5.0.375.12" />
        <vers num="5.0.375.13" />
        <vers num="5.0.375.14" />
        <vers num="5.0.375.15" />
        <vers num="5.0.375.16" />
        <vers num="5.0.375.17" />
        <vers num="5.0.375.18" />
        <vers num="5.0.375.19" />
        <vers num="5.0.375.2" />
        <vers num="5.0.375.20" />
        <vers num="5.0.375.21" />
        <vers num="5.0.375.22" />
        <vers num="5.0.375.23" />
        <vers num="5.0.375.25" />
        <vers num="5.0.375.26" />
        <vers num="5.0.375.27" />
        <vers num="5.0.375.28" />
        <vers num="5.0.375.29" />
        <vers num="5.0.375.3" />
        <vers num="5.0.375.30" />
        <vers num="5.0.375.31" />
        <vers num="5.0.375.32" />
        <vers num="5.0.375.33" />
        <vers num="5.0.375.34" />
        <vers num="5.0.375.35" />
        <vers num="5.0.375.36" />
        <vers num="5.0.375.37" />
        <vers num="5.0.375.38" />
        <vers num="5.0.375.39" />
        <vers num="5.0.375.4" />
        <vers num="5.0.375.40" />
        <vers num="5.0.375.41" />
        <vers num="5.0.375.42" />
        <vers num="5.0.375.43" />
        <vers num="5.0.375.44" />
        <vers num="5.0.375.45" />
        <vers num="5.0.375.46" />
        <vers num="5.0.375.47" />
        <vers num="5.0.375.48" />
        <vers num="5.0.375.49" />
        <vers num="5.0.375.5" />
        <vers num="5.0.375.50" />
        <vers num="5.0.375.51" />
        <vers num="5.0.375.52" />
        <vers num="5.0.375.53" />
        <vers prev="1" num="5.0.375.54" />
        <vers num="5.0.375.6" />
        <vers num="5.0.375.7" />
        <vers num="5.0.375.8" />
        <vers num="5.0.375.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2111" published="2010-05-28" name="CVE-2010-2111" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58934" source="XF">pacific-timesheet-unspecified-csrf(58934)</ref>
      <ref url="http://secunia.com/advisories/39951" source="SECUNIA" adv="1">39951</ref>
      <ref url="http://osvdb.org/64924" source="OSVDB">64924</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/pacific-timesheet-674-cross-site.html" source="MISC" adv="1">http://cross-site-scripting.blogspot.com/2010/05/pacific-timesheet-674-cross-site.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pacifictimesheet" name="pacific_timesheet">
        <vers num="6.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2010-2112" published="2010-05-28" name="CVE-2010-2112" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:N)" CVSS_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_base_score="8.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FTP service in FileCOPA before 5.03 allows remote attackers to read or overwrite arbitrary files via unknown vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39843" source="SECUNIA" adv="1">39843</ref>
      <ref url="http://osvdb.org/64823" source="OSVDB">64823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intervations" name="filecopa">
        <vers num="1.01" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="3.01" />
        <vers num="4.01" />
        <vers prev="1" num="5.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2113" published="2010-05-28" name="CVE-2010-2113" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in The Uniform Server 5.6.5 allow remote attackers to hijack the authentication of administrators for requests that change passwords via (1) apsetup.php, (2) psetup.php, (3) sslpsetup.php, or (4) mqsetup.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/58844" source="XF">uniform-server-unspecified-csrf(58844)</ref>
      <ref url="http://secunia.com/advisories/39913" source="SECUNIA" adv="1">39913</ref>
      <ref url="http://osvdb.org/64858" source="OSVDB">64858</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/uniform-server-565-xsrf.html" source="MISC">http://cross-site-scripting.blogspot.com/2010/05/uniform-server-565-xsrf.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uniformserver" name="uniformserver">
        <vers num="5.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2010-2114" published="2010-05-28" name="CVE-2010-2114" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in pbx/gate in Brekeke PBX 2.4.4.8 allows remote attackers to hijack the authentication of users for requests that change passwords via the pbxadmin.web.PbxUserEdit bean.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/39952" source="SECUNIA" adv="1">39952</ref>
      <ref url="http://osvdb.org/64950" source="OSVDB">64950</ref>
      <ref url="http://cross-site-scripting.blogspot.com/2010/05/brekeke-pbx-2448-cross-site-request.html" source="MISC">http://cross-site-scripting.blogspot.com/2010/05/brekeke-pbx-2448-cross-site-request.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brekeke" name="pbx">
        <vers num="2.4.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2010-2115" published="2010-05-28" name="CVE-2010-2115" modified="2010-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L
