<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-22" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="Medium" seq="2011-0001" published="2011-03-15" name="CVE-2011-0001" modified="2011-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=667261" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=667261</ref>
      <ref url="https://bugzilla.redhat.com/attachment.cgi?id=473779&amp;action=diff" source="MISC" patch="1">https://bugzilla.redhat.com/attachment.cgi?id=473779&amp;action=diff</ref>
      <ref url="http://lists.wpkg.org/pipermail/stgt/2011-March/004473.html" source="MLIST" patch="1">[stgt] 20110309 [PATCH] iscsi: fix buffer overflow before login</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66010" source="XF">lstf-iscsirxhandler-dos(66010)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0636" source="VUPEN" adv="1">ADV-2011-0636</ref>
      <ref url="http://www.securitytracker.com/id?1025184" source="SECTRACK">1025184</ref>
      <ref url="http://www.securityfocus.com/bid/46817" source="BID">46817</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0332.html" source="REDHAT">RHSA-2011:0332</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2209" source="DEBIAN">DSA-2209</ref>
      <ref url="http://secunia.com/advisories/43713" source="SECUNIA" adv="1">43713</ref>
      <ref url="http://secunia.com/advisories/43706" source="SECUNIA" adv="1">43706</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zaal" name="tgt">
        <vers num="0.9.5"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers prev="1" num="1.0.13"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0002" published="2011-01-22" name="CVE-2011-0002" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57" source="CONFIRM">https://fedorahosted.org/libuser/browser/NEWS?rev=libuser-0.57</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=643227" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=643227</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64677" source="XF">libuser-password-security-bypass(64677)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0226" source="VUPEN">ADV-2011-0226</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0201" source="VUPEN">ADV-2011-0201</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0184" source="VUPEN" adv="1">ADV-2011-0184</ref>
      <ref url="http://www.securityfocus.com/bid/45791" source="BID">45791</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0170.html" source="REDHAT">RHSA-2011:0170</ref>
      <ref url="http://www.osvdb.org/70421" source="OSVDB">70421</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:019" source="MANDRIVA">MDVSA-2011:019</ref>
      <ref url="http://securitytracker.com/id?1024960" source="SECTRACK">1024960</ref>
      <ref url="http://secunia.com/advisories/43047" source="SECUNIA">43047</ref>
      <ref url="http://secunia.com/advisories/42966" source="SECUNIA" adv="1">42966</ref>
      <ref url="http://secunia.com/advisories/42891" source="SECUNIA" adv="1">42891</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053378.html" source="FEDORA">FEDORA-2011-0320</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053365.html" source="FEDORA">FEDORA-2011-0316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="miloslav_trmac" name="libuser">
        <vers num="0.1"/>
        <vers num="0.10"/>
        <vers num="0.11"/>
        <vers num="0.16.1"/>
        <vers num="0.18"/>
        <vers num="0.2"/>
        <vers num="0.20"/>
        <vers num="0.21"/>
        <vers num="0.23"/>
        <vers num="0.24-3"/>
        <vers num="0.24-4"/>
        <vers num="0.25"/>
        <vers num="0.25.1"/>
        <vers num="0.26"/>
        <vers num="0.27"/>
        <vers num="0.28"/>
        <vers num="0.29"/>
        <vers num="0.3"/>
        <vers num="0.30"/>
        <vers num="0.31"/>
        <vers num="0.32"/>
        <vers num="0.4"/>
        <vers num="0.49.100"/>
        <vers num="0.49.101-1"/>
        <vers num="0.49.101-2"/>
        <vers num="0.49.102"/>
        <vers num="0.49.90"/>
        <vers num="0.49.91"/>
        <vers num="0.49.92"/>
        <vers num="0.49.93"/>
        <vers num="0.49.95"/>
        <vers num="0.49.96"/>
        <vers num="0.49.97"/>
        <vers num="0.49.98"/>
        <vers num="0.49.99"/>
        <vers num="0.5"/>
        <vers num="0.50"/>
        <vers num="0.50.2"/>
        <vers num="0.51"/>
        <vers num="0.51.1-1"/>
        <vers num="0.51.1-2"/>
        <vers num="0.51.10"/>
        <vers num="0.51.11"/>
        <vers num="0.51.12"/>
        <vers num="0.51.2"/>
        <vers num="0.51.4"/>
        <vers num="0.51.5"/>
        <vers num="0.51.6"/>
        <vers num="0.51.7"/>
        <vers num="0.51.7-3"/>
        <vers num="0.51.7-7"/>
        <vers num="0.51.8"/>
        <vers num="0.51.9"/>
        <vers num="0.52"/>
        <vers num="0.52.1"/>
        <vers num="0.52.2"/>
        <vers num="0.52.3"/>
        <vers num="0.52.4"/>
        <vers num="0.52.5"/>
        <vers num="0.52.6"/>
        <vers num="0.53"/>
        <vers num="0.53.1"/>
        <vers num="0.53.2"/>
        <vers num="0.53.3"/>
        <vers num="0.53.4"/>
        <vers num="0.53.5"/>
        <vers num="0.53.6"/>
        <vers num="0.53.7"/>
        <vers num="0.53.8"/>
        <vers num="0.54"/>
        <vers num="0.54.1"/>
        <vers num="0.54.2"/>
        <vers num="0.54.3"/>
        <vers num="0.54.4"/>
        <vers num="0.54.5"/>
        <vers num="0.54.6"/>
        <vers num="0.54.7"/>
        <vers num="0.54.8"/>
        <vers num="0.55"/>
        <vers num="0.56"/>
        <vers num="0.56.1"/>
        <vers num="0.56.10"/>
        <vers num="0.56.11"/>
        <vers num="0.56.12"/>
        <vers num="0.56.13"/>
        <vers num="0.56.14"/>
        <vers num="0.56.15"/>
        <vers num="0.56.16"/>
        <vers num="0.56.17"/>
        <vers prev="1" num="0.56.18"/>
        <vers num="0.56.2"/>
        <vers num="0.56.3"/>
        <vers num="0.56.4"/>
        <vers num="0.56.5"/>
        <vers num="0.56.6"/>
        <vers num="0.56.7"/>
        <vers num="0.56.8"/>
        <vers num="0.56.9"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0003" published="2011-01-10" name="CVE-2011-0003" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">MediaWiki before 1.16.1, when user or site JavaScript or CSS is enabled, allows remote attackers to conduct clickjacking attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-January/000093.html" source="MLIST" patch="1" adv="1">[MediaWiki-announce] 20110104 MediaWiki security release 1.16.1</ref>
      <ref url="https://bugzilla.wikimedia.org/show_bug.cgi?id=26561" source="CONFIRM">https://bugzilla.wikimedia.org/show_bug.cgi?id=26561</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64476" source="XF">mediawiki-frames-clickjacking(64476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0017" source="VUPEN" adv="1">ADV-2011-0017</ref>
      <ref url="http://www.osvdb.org/70272" source="OSVDB">70272</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/04/6" source="MLIST">[oss-security] 20110104 (possible) CVE request: Clickjacking in Mediawiki</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/04/12" source="MLIST">[oss-security] 20110104 Re: (possible) CVE request: Clickjacking in Mediawiki</ref>
      <ref url="http://secunia.com/advisories/42810" source="SECUNIA" adv="1">42810</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html" source="FEDORA">FEDORA-2011-5807</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html" source="FEDORA">FEDORA-2011-5812</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html" source="FEDORA">FEDORA-2011-5848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0"/>
        <vers num="1.10.0" edition="rc1"/>
        <vers num="1.10.0" edition="rc2"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="1.11" edition="rc1"/>
        <vers num="1.11.0" edition="rc1"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.12.0" edition="rc1"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.3"/>
        <vers num="1.12.4"/>
        <vers num="1.13.0" edition="rc1"/>
        <vers num="1.13.0" edition="rc2"/>
        <vers num="1.13.1"/>
        <vers num="1.13.2"/>
        <vers num="1.13.3"/>
        <vers num="1.13.4"/>
        <vers num="1.14.0" edition="rc1"/>
        <vers num="1.14.1"/>
        <vers num="1.15.0" edition="rc1"/>
        <vers num="1.15.1"/>
        <vers num="1.15.2"/>
        <vers num="1.15.3"/>
        <vers prev="1" num="1.16.0" edition="beta1"/>
        <vers prev="1" num="1.16.0" edition="beta2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4" edition="beta1"/>
        <vers num="1.4" edition="beta2"/>
        <vers num="1.4" edition="beta3"/>
        <vers num="1.4" edition="beta4"/>
        <vers num="1.4" edition="beta5"/>
        <vers num="1.4" edition="beta6"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers num="1.4.14"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.5" edition="alpha1"/>
        <vers num="1.5" edition="alpha2"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5" edition="beta3"/>
        <vers num="1.5" edition="beta4"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5" edition="rc3"/>
        <vers num="1.5" edition="rc4"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.10"/>
        <vers num="1.6.12"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.5_r14348"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.9.0" edition="rc2"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="stable_2003-08-29"/>
        <vers num="stable_2003-11-07"/>
        <vers num="stable_2003-11-17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0004" published="2011-01-10" name="CVE-2011-0004" modified="2011-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://piwik.org/blog/2011/01/professional-security-audit-in-piwik/" source="CONFIRM" patch="1">http://piwik.org/blog/2011/01/professional-security-audit-in-piwik/</ref>
      <ref url="http://piwik.org/blog/2011/01/piwik-1-1-security-advisory/" source="CONFIRM" patch="1" adv="1">http://piwik.org/blog/2011/01/piwik-1-1-security-advisory/</ref>
      <ref url="http://piwik.org/blog/2011/01/piwik-1-1-2/" source="CONFIRM" patch="1">http://piwik.org/blog/2011/01/piwik-1-1-2/</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/06/15" source="MLIST" patch="1">[oss-security] 20110106 Re: CVE Request: Multiple XSS Vulnerabiliies &lt; Piwik 1.1</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/06/1" source="MLIST" patch="1">[oss-security] 20110105 CVE Request: Multiple XSS Vulnerabiliies &lt; Piwik 1.1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0013" source="VUPEN">ADV-2011-0013</ref>
      <ref url="http://www.securityfocus.com/bid/45659" source="BID">45659</ref>
      <ref url="http://secunia.com/advisories/42809" source="SECUNIA" adv="1">42809</ref>
      <ref url="http://osvdb.org/70310" source="OSVDB">70310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="piwik" name="piwik">
        <vers num="0.1"/>
        <vers num="0.1.1"/>
        <vers num="0.1.10"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.1.4"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.1.7"/>
        <vers num="0.1.8"/>
        <vers num="0.1.9"/>
        <vers num="0.2.1"/>
        <vers num="0.2.10"/>
        <vers num="0.2.11"/>
        <vers num="0.2.12"/>
        <vers num="0.2.13"/>
        <vers num="0.2.14"/>
        <vers num="0.2.16"/>
        <vers num="0.2.17"/>
        <vers num="0.2.18"/>
        <vers num="0.2.19"/>
        <vers num="0.2.2"/>
        <vers num="0.2.20"/>
        <vers num="0.2.22"/>
        <vers num="0.2.23"/>
        <vers num="0.2.24"/>
        <vers num="0.2.25"/>
        <vers num="0.2.26"/>
        <vers num="0.2.27"/>
        <vers num="0.2.28"/>
        <vers num="0.2.29"/>
        <vers num="0.2.3"/>
        <vers num="0.2.30"/>
        <vers num="0.2.31"/>
        <vers num="0.2.32"/>
        <vers num="0.2.33"/>
        <vers num="0.2.34"/>
        <vers num="0.2.35"/>
        <vers num="0.2.36"/>
        <vers num="0.2.37"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
        <vers num="0.2.8"/>
        <vers num="0.2.9"/>
        <vers num="0.4" edition="rc1"/>
        <vers num="0.4" edition="rc2"/>
        <vers num="0.4" edition="rc3"/>
        <vers num="0.4.1" edition="rc1"/>
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="0.4.4"/>
        <vers num="0.4.5"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers num="0.5.3"/>
        <vers num="0.5.4"/>
        <vers num="0.5.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.6.3" edition="rc1"/>
        <vers num="0.6.3" edition="rc2"/>
        <vers num="0.6.4"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="0.9.9"/>
        <vers prev="1" num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0005" published="2011-01-10" name="CVE-2011-0005" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attackers to inject arbitrary web script or HTML via the ordering parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://yehg.net/lab/pr0js/advisories/joomla/core/%5Bjoomla_1.0.x~15%5D_cross_site_scripting" source="MISC">http://yehg.net/lab/pr0js/advisories/joomla/core/[joomla_1.0.x~15]_cross_site_scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64539" source="XF">joomla-ordering-xss(64539)</ref>
      <ref url="http://www.securityfocus.com/bid/45679" source="BID">45679</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515590/100/0/threaded" source="BUGTRAQ">20110107 Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515553/100/0/threaded" source="BUGTRAQ">20110105 Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability</ref>
      <ref url="http://packetstormsecurity.org/files/view/97273/joomla1015-xss.txt" source="MISC">http://packetstormsecurity.org/files/view/97273/joomla1015-xss.txt</ref>
      <ref url="http://osvdb.org/70369" source="OSVDB">70369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_search">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0006" published="2012-06-21" name="CVE-2011-0006" modified="2012-06-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunistic circumstances by leveraging an administrator's addition of an IMA rule for LSM.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://github.com/torvalds/linux/commit/867c20265459d30a01b021a9c1e81fb4c5832aa9" source="CONFIRM" patch="1">https://github.com/torvalds/linux/commit/867c20265459d30a01b021a9c1e81fb4c5832aa9</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=867c20265459d30a01b021a9c1e81fb4c5832aa9" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=867c20265459d30a01b021a9c1e81fb4c5832aa9</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=667912" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=667912</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/06/18" source="MLIST">[oss-security] 20110106 Re: CVE Request: kernel [Re: Security review of 2.6.32.28]</ref>
      <ref url="http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37" source="CONFIRM">http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.36.1"/>
        <vers num="2.6.36.2"/>
        <vers num="2.6.36.3"/>
        <vers prev="1" num="2.6.36.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0007" published="2011-01-10" name="CVE-2011-0007" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is sent.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/07/3" source="MLIST" patch="1">[oss-security] 20110107 CVE Request - pimd - Insecure file creation in /var/tmp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64528" source="XF">pimd-pimd-symlink(64528)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0113" source="VUPEN">ADV-2011-0113</ref>
      <ref url="http://www.securityfocus.com/bid/45715" source="BID">45715</ref>
      <ref url="http://www.osvdb.org/70305" source="OSVDB">70305</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/07/4" source="MLIST">[oss-security] 20110107 Re: CVE Request - pimd - Insecure file creation in /var/tmp</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2147" source="DEBIAN">DSA-2147</ref>
      <ref url="http://secunia.com/advisories/42793" source="SECUNIA">42793</ref>
      <ref url="http://secunia.com/advisories/42759" source="SECUNIA" adv="1">42759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="troglobit" name="pimd">
        <vers num="2.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0008" published="2011-01-20" name="CVE-2011-0008" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.  NOTE: this vulnerability exists because of a CVE-2009-0034 regression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=668843" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=668843</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64965" source="XF">sudo-parse-privilege-escalation(64965)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0199" source="VUPEN">ADV-2011-0199</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0195" source="VUPEN">ADV-2011-0195</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:018" source="MANDRIVA">MDVSA-2011:018</ref>
      <ref url="http://secunia.com/advisories/42968" source="SECUNIA" adv="1">42968</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html" source="FEDORA">FEDORA-2011-0455</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html" source="FEDORA">FEDORA-2011-0470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.3.1"/>
        <vers num="1.5"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.2p1"/>
        <vers num="1.6.2p2"/>
        <vers num="1.6.2p3"/>
        <vers num="1.6.3"/>
        <vers num="1.6.3_p1"/>
        <vers num="1.6.3_p2"/>
        <vers num="1.6.3_p3"/>
        <vers num="1.6.3_p4"/>
        <vers num="1.6.3_p5"/>
        <vers num="1.6.3_p6"/>
        <vers num="1.6.3_p7"/>
        <vers num="1.6.3p1"/>
        <vers num="1.6.3p2"/>
        <vers num="1.6.3p3"/>
        <vers num="1.6.3p4"/>
        <vers num="1.6.3p5"/>
        <vers num="1.6.3p6"/>
        <vers num="1.6.3p7"/>
        <vers num="1.6.4"/>
        <vers num="1.6.4_p1"/>
        <vers num="1.6.4_p2"/>
        <vers num="1.6.4p1"/>
        <vers num="1.6.4p2"/>
        <vers num="1.6.5"/>
        <vers num="1.6.5_p1"/>
        <vers num="1.6.5_p2"/>
        <vers num="1.6.5p1"/>
        <vers num="1.6.5p2"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.7_p5"/>
        <vers num="1.6.7p1"/>
        <vers num="1.6.7p2"/>
        <vers num="1.6.7p3"/>
        <vers num="1.6.7p4"/>
        <vers num="1.6.7p5"/>
        <vers num="1.6.8"/>
        <vers num="1.6.8_p1"/>
        <vers num="1.6.8_p12"/>
        <vers num="1.6.8_p2"/>
        <vers num="1.6.8_p5"/>
        <vers num="1.6.8_p7"/>
        <vers num="1.6.8_p8"/>
        <vers num="1.6.8_p9"/>
        <vers num="1.6.8p1"/>
        <vers num="1.6.8p10"/>
        <vers num="1.6.8p11"/>
        <vers num="1.6.8p12"/>
        <vers num="1.6.8p2"/>
        <vers num="1.6.8p3"/>
        <vers num="1.6.8p4"/>
        <vers num="1.6.8p5"/>
        <vers num="1.6.8p6"/>
        <vers num="1.6.8p7"/>
        <vers num="1.6.8p8"/>
        <vers num="1.6.8p9"/>
        <vers num="1.6.9"/>
        <vers num="1.6.9_p17"/>
        <vers num="1.6.9_p18"/>
        <vers num="1.6.9_p19"/>
        <vers num="1.6.9_p20"/>
        <vers num="1.6.9_p21"/>
        <vers num="1.6.9_p22"/>
        <vers num="1.6.9p1"/>
        <vers num="1.6.9p10"/>
        <vers num="1.6.9p11"/>
        <vers num="1.6.9p12"/>
        <vers num="1.6.9p13"/>
        <vers num="1.6.9p14"/>
        <vers num="1.6.9p15"/>
        <vers num="1.6.9p16"/>
        <vers num="1.6.9p17"/>
        <vers num="1.6.9p18"/>
        <vers num="1.6.9p19"/>
        <vers num="1.6.9p2"/>
        <vers num="1.6.9p20"/>
        <vers num="1.6.9p21"/>
        <vers num="1.6.9p22"/>
        <vers num="1.6.9p23"/>
        <vers num="1.6.9p3"/>
        <vers num="1.6.9p4"/>
        <vers num="1.6.9p5"/>
        <vers num="1.6.9p6"/>
        <vers num="1.6.9p7"/>
        <vers num="1.6.9p8"/>
        <vers num="1.6.9p9"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.2p1"/>
        <vers num="1.7.2p2"/>
        <vers num="1.7.2p3"/>
        <vers num="1.7.2p4"/>
        <vers num="1.7.2p5"/>
        <vers num="1.7.2p6"/>
        <vers num="1.7.2p7"/>
        <vers num="1.7.3b1"/>
        <vers num="1.7.4"/>
        <vers num="1.7.4p1"/>
        <vers num="1.7.4p2"/>
        <vers num="1.7.4p3"/>
        <vers num="1.7.4p4"/>
        <vers prev="1" num="1.7.4p5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0009" published="2011-01-25" name="CVE-2011-0009" modified="2011-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determine cleartext passwords via a brute-force attack on the database.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=672250" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=672250</ref>
      <ref url="http://lists.bestpractical.com/pipermail/rt-announce/2011-January/000185.html" source="MLIST" patch="1">[rt-announce] 20110119 Security vulnerability in RT 3.0 and up</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610850</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0576" source="VUPEN" adv="1">ADV-2011-0576</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0475" source="VUPEN" adv="1">ADV-2011-0475</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0190" source="VUPEN" adv="1">ADV-2011-0190</ref>
      <ref url="http://www.securityfocus.com/bid/45959" source="BID">45959</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2150" source="DEBIAN">DSA-2150</ref>
      <ref url="http://secunia.com/advisories/43438" source="SECUNIA" adv="1">43438</ref>
      <ref url="http://osvdb.org/70661" source="OSVDB">70661</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054740.html" source="FEDORA">FEDORA-2011-1677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bestpractical" name="rt">
        <vers num="3.0.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10" edition="pre1"/>
        <vers num="3.0.10" edition="pre2"/>
        <vers num="3.0.10" edition="rc1"/>
        <vers num="3.0.11" edition="rc2"/>
        <vers num="3.0.11" edition="rc3"/>
        <vers num="3.0.11" edition="rc4"/>
        <vers num="3.0.12"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.7.1"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.12"/>
        <vers num="3.1.13"/>
        <vers num="3.1.14"/>
        <vers num="3.1.15"/>
        <vers num="3.1.16"/>
        <vers num="3.1.17"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.2.0" edition="rc1"/>
        <vers num="3.2.0" edition="rc2"/>
        <vers num="3.2.0" edition="rc3"/>
        <vers num="3.2.0" edition="rc4"/>
        <vers num="3.2.1" edition="rc1"/>
        <vers num="3.2.1" edition="rc2"/>
        <vers num="3.2.1" edition="rc3"/>
        <vers num="3.2.1" edition="rc4"/>
        <vers num="3.2.2" edition="rc1"/>
        <vers num="3.2.3" edition="rc1"/>
        <vers num="3.2.3" edition="rc2"/>
        <vers num="3.4.0" edition="rc1"/>
        <vers num="3.4.0" edition="rc2"/>
        <vers num="3.4.0" edition="rc3"/>
        <vers num="3.4.0" edition="rc4"/>
        <vers num="3.4.0" edition="rc5"/>
        <vers num="3.4.0" edition="rc6"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2" edition="rc1"/>
        <vers num="3.4.2" edition="rc2"/>
        <vers num="3.4.3" edition="rc1"/>
        <vers num="3.4.3" edition="rc2"/>
        <vers num="3.4.4" edition="pre1"/>
        <vers num="3.4.4" edition="pre2"/>
        <vers num="3.4.4" edition="pre3"/>
        <vers num="3.4.5" edition="pre1"/>
        <vers num="3.4.5" edition="rc1"/>
        <vers num="3.4.5" edition="rc2"/>
        <vers num="3.4.6" edition="rc1"/>
        <vers num="3.4.6" edition="rc2"/>
        <vers num="3.4.7" edition="rc1"/>
        <vers num="3.5.1"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.6.0" edition="pre0"/>
        <vers num="3.6.0" edition="pre1"/>
        <vers num="3.6.0" edition="rc1"/>
        <vers num="3.6.0" edition="rc2"/>
        <vers num="3.6.0" edition="rc3"/>
        <vers num="3.6.1" edition="pre2"/>
        <vers num="3.6.1" edition="rc1"/>
        <vers num="3.6.1" edition="rc2"/>
        <vers num="3.6.2" edition="rc1"/>
        <vers num="3.6.2" edition="rc3"/>
        <vers num="3.6.2" edition="rc4"/>
        <vers num="3.6.2" edition="rc5"/>
        <vers num="3.6.3" edition="rc1"/>
        <vers num="3.6.3" edition="rc2"/>
        <vers num="3.6.3" edition="rc3"/>
        <vers num="3.6.3" edition="rc4"/>
        <vers num="3.6.4" edition="rc1"/>
        <vers num="3.6.4" edition="rc2"/>
        <vers num="3.6.5" edition="rc1"/>
        <vers num="3.6.5" edition="rc2"/>
        <vers num="3.6.6" edition="rc1"/>
        <vers num="3.6.6" edition="rc2"/>
        <vers num="3.6.6" edition="rc3"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="3.7.1"/>
        <vers num="3.7.5"/>
        <vers num="3.7.80"/>
        <vers num="3.7.85"/>
        <vers num="3.7.86"/>
        <vers num="3.8.0" edition="rc1"/>
        <vers num="3.8.0" edition="rc2"/>
        <vers num="3.8.0" edition="rc3"/>
        <vers num="3.8.1" edition="rc1"/>
        <vers num="3.8.1" edition="rc2"/>
        <vers num="3.8.1" edition="rc3"/>
        <vers num="3.8.1" edition="rc4"/>
        <vers num="3.8.1" edition="rc5"/>
        <vers num="3.8.2" edition="rc1"/>
        <vers num="3.8.2" edition="rc2"/>
        <vers num="3.8.3" edition="rc1"/>
        <vers num="3.8.3" edition="rc2"/>
        <vers num="3.8.4" edition="rc1"/>
        <vers num="3.8.5"/>
        <vers num="3.8.6" edition="rc1"/>
        <vers num="3.8.7" edition="rc1"/>
        <vers num="3.8.8" edition="rc2"/>
        <vers num="3.8.8" edition="rc3"/>
        <vers num="3.8.8" edition="rc4"/>
        <vers prev="1" num="3.8.9" edition="rc1"/>
        <vers num="4.0.0" edition="rc1"/>
        <vers num="4.0.0" edition="rc2"/>
        <vers num="4.0.0" edition="rc3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0010" published="2011-01-18" name="CVE-2011-0010" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=668879" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=668879</ref>
      <ref url="http://www.sudo.ws/repos/sudo/rev/fe8a94f96542" source="CONFIRM" patch="1">http://www.sudo.ws/repos/sudo/rev/fe8a94f96542</ref>
      <ref url="http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e" source="MISC" patch="1">http://www.sudo.ws/repos/sudo/rev/07d1b0ce530e</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/12/1" source="MLIST" patch="1">[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/11/3" source="MLIST" patch="1">[oss-security] 20110111 CVE request: sudo does not ask for password on GID changes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64636" source="XF">sudo-groupid-privilege-escalation(64636)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0362" source="VUPEN">ADV-2011-0362</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0199" source="VUPEN">ADV-2011-0199</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0195" source="VUPEN">ADV-2011-0195</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0182" source="VUPEN">ADV-2011-0182</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0089" source="VUPEN" adv="1">ADV-2011-0089</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1046-1" source="UBUNTU">USN-1046-1</ref>
      <ref url="http://www.sudo.ws/sudo/alerts/runas_group_pw.html" source="CONFIRM">http://www.sudo.ws/sudo/alerts/runas_group_pw.html</ref>
      <ref url="http://www.securityfocus.com/bid/45774" source="BID">45774</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0599.html" source="REDHAT">RHSA-2011:0599</ref>
      <ref url="http://www.osvdb.org/70400" source="OSVDB">70400</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:018" source="MANDRIVA">MDVSA-2011:018</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.593654" source="SLACKWARE">SSA:2011-041-05</ref>
      <ref url="http://secunia.com/advisories/43282" source="SECUNIA">43282</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/42968" source="SECUNIA">42968</ref>
      <ref url="http://secunia.com/advisories/42949" source="SECUNIA">42949</ref>
      <ref url="http://secunia.com/advisories/42886" source="SECUNIA" adv="1">42886</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/12/3" source="MLIST">[oss-security] 20110112 Re: CVE request: sudo does not ask for password on GID changes</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053341.html" source="FEDORA">FEDORA-2011-0455</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053263.html" source="FEDORA">FEDORA-2011-0470</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.2p1"/>
        <vers num="1.7.2p2"/>
        <vers num="1.7.2p3"/>
        <vers num="1.7.2p4"/>
        <vers num="1.7.2p5"/>
        <vers num="1.7.2p6"/>
        <vers num="1.7.2p7"/>
        <vers num="1.7.3b1"/>
        <vers num="1.7.4"/>
        <vers num="1.7.4p1"/>
        <vers num="1.7.4p2"/>
        <vers num="1.7.4p3"/>
        <vers num="1.7.4p4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0011" published="2012-06-21" name="CVE-2011-0011" modified="2012-06-21" CVSS_version="2.0" CVSS_vector="(AV:A/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.2" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197" source="MISC">https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65215" source="XF">qemu-vnc-security-bypass(65215)</ref>
      <ref url="http://www.osvdb.org/70992" source="OSVDB">70992</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/12/2" source="MLIST">[oss-security] 20110112 Re: CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/11/1" source="MLIST">[oss-security] 20110110 Re: CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/10/3" source="MLIST">[oss-security] 20110110 CVE request: qemu-kvm: Setting VNC password to  empty string silently disables all authentication</ref>
      <ref url="http://ubuntu.com/usn/usn-1063-1" source="UBUNTU">USN-1063-1</ref>
      <ref url="http://secunia.com/advisories/44393" source="SECUNIA" adv="1">44393</ref>
      <ref url="http://secunia.com/advisories/43733" source="SECUNIA" adv="1">43733</ref>
      <ref url="http://secunia.com/advisories/43272" source="SECUNIA" adv="1">43272</ref>
      <ref url="http://secunia.com/advisories/42830" source="SECUNIA" adv="1">42830</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2011-0345.html" source="REDHAT">RHSA-2011:0345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qemu" name="qemu">
        <vers num="0.1"/>
        <vers num="0.1.1"/>
        <vers num="0.1.2"/>
        <vers num="0.1.3"/>
        <vers num="0.1.4"/>
        <vers num="0.1.5"/>
        <vers num="0.1.6"/>
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.10.5"/>
        <vers num="0.10.6"/>
        <vers prev="1" num="0.11.0" edition="rc0"/>
        <vers prev="1" num="0.11.0" edition="rc1"/>
        <vers prev="1" num="0.11.0" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0012" published="2011-04-18" name="CVE-2011-0012" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=639869" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=639869</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0899" source="VUPEN" adv="1">ADV-2011-0899</ref>
      <ref url="http://www.securitytracker.com/id?1025304" source="SECTRACK">1025304</ref>
      <ref url="http://www.securityfocus.com/bid/47269" source="BID">47269</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0426.html" source="REDHAT">RHSA-2011:0426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="spice-xpi">
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0013" published="2011-02-18" name="CVE-2011-0013" modified="2012-11-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=675786" source="MISC" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=675786</ref>
      <ref url="http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html#Fixed_in_Apache_Tomcat_6.0.30</ref>
      <ref url="http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html#Fixed_in_Apache_Tomcat_5.5.32</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0376" source="VUPEN" adv="1">ADV-2011-0376</ref>
      <ref url="http://www.securitytracker.com/id?1025026" source="SECTRACK">1025026</ref>
      <ref url="http://www.securityfocus.com/bid/46174" source="BID">46174</ref>
      <ref url="http://www.securityfocus.com/archive/1/516209/30/90/threaded" source="BUGTRAQ">20110205 [SECURITY] CVE-2011-0013 Apache Tomcat Manager XSS vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1845.html" source="REDHAT">RHSA-2011:1845</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0897.html" source="REDHAT">RHSA-2011:0897</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0896.html" source="REDHAT">RHSA-2011:0896</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0791.html" source="REDHAT">RHSA-2011:0791</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:030" source="MANDRIVA">MDVSA-2011:030</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2160" source="DEBIAN">DSA-2160</ref>
      <ref url="http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_%28released_14_Jan_2011%29" source="CONFIRM">http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.6_(released_14_Jan_2011)</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html" source="CONFIRM">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5098550.html</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://securityreason.com/securityalert/8093" source="SREASON">8093</ref>
      <ref url="http://secunia.com/advisories/45022" source="SECUNIA">45022</ref>
      <ref url="http://secunia.com/advisories/43192" source="SECUNIA" adv="1">43192</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14945" source="OVAL">oval:org.mitre.oval:def:14945</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12878" source="OVAL">oval:org.mitre.oval:def:12878</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=132215163318824&amp;w=2" source="HP">SSRT100627</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=132215163318824&amp;w=2" source="HP">HPSBUX02725</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="5.5.0"/>
        <vers num="5.5.1"/>
        <vers num="5.5.10"/>
        <vers num="5.5.11"/>
        <vers num="5.5.12"/>
        <vers num="5.5.13"/>
        <vers num="5.5.14"/>
        <vers num="5.5.15"/>
        <vers num="5.5.16"/>
        <vers num="5.5.17"/>
        <vers num="5.5.18"/>
        <vers num="5.5.19"/>
        <vers num="5.5.2"/>
        <vers num="5.5.20"/>
        <vers num="5.5.21"/>
        <vers num="5.5.22"/>
        <vers num="5.5.23"/>
        <vers num="5.5.24"/>
        <vers num="5.5.25"/>
        <vers num="5.5.26"/>
        <vers num="5.5.27"/>
        <vers num="5.5.28"/>
        <vers num="5.5.29"/>
        <vers num="5.5.3"/>
        <vers num="5.5.30"/>
        <vers num="5.5.31"/>
        <vers num="5.5.4"/>
        <vers num="5.5.5"/>
        <vers num="5.5.6"/>
        <vers num="5.5.7"/>
        <vers num="5.5.8"/>
        <vers num="5.5.9"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.12"/>
        <vers num="6.0.13"/>
        <vers num="6.0.14"/>
        <vers num="6.0.15"/>
        <vers num="6.0.16"/>
        <vers num="6.0.17"/>
        <vers num="6.0.18"/>
        <vers num="6.0.19"/>
        <vers num="6.0.2"/>
        <vers num="6.0.20"/>
        <vers num="6.0.24"/>
        <vers num="6.0.26"/>
        <vers num="6.0.27"/>
        <vers num="6.0.28"/>
        <vers num="6.0.29"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0014" published="2011-02-18" name="CVE-2011-0014" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openssl.org/news/secadv_20110208.txt" source="CONFIRM" patch="1" adv="1">http://www.openssl.org/news/secadv_20110208.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0603" source="VUPEN">ADV-2011-0603</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0399" source="VUPEN" adv="1">ADV-2011-0399</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0395" source="VUPEN" adv="1">ADV-2011-0395</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0389" source="VUPEN" adv="1">ADV-2011-0389</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0387" source="VUPEN" adv="1">ADV-2011-0387</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0361" source="VUPEN" adv="1">ADV-2011-0361</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1064-1" source="UBUNTU">USN-1064-1</ref>
      <ref url="http://www.securitytracker.com/id?1025050" source="SECTRACK">1025050</ref>
      <ref url="http://www.securityfocus.com/bid/46264" source="BID">46264</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0677.html" source="REDHAT">RHSA-2011:0677</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:028" source="MANDRIVA">MDVSA-2011:028</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2162" source="DEBIAN">DSA-2162</ref>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.668823" source="SLACKWARE">SSA:2011-041-04</ref>
      <ref url="http://secunia.com/advisories/44269" source="SECUNIA">44269</ref>
      <ref url="http://secunia.com/advisories/43339" source="SECUNIA" adv="1">43339</ref>
      <ref url="http://secunia.com/advisories/43301" source="SECUNIA" adv="1">43301</ref>
      <ref url="http://secunia.com/advisories/43286" source="SECUNIA" adv="1">43286</ref>
      <ref url="http://secunia.com/advisories/43227" source="SECUNIA" adv="1">43227</ref>
      <ref url="http://osvdb.org/70847" source="OSVDB">70847</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=131042179515633&amp;w=2" source="HP">HPSBUX02689</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=131042179515633&amp;w=2" source="HP">SSRT100494</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054007.html" source="FEDORA">FEDORA-2011-1273</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777" source="HP">HPSBMA02658</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777" source="HP">SSRT100413</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-002.txt.asc" source="NETBSD">NetBSD-SA2011-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8h"/>
        <vers num="0.9.8i"/>
        <vers num="0.9.8j"/>
        <vers num="0.9.8k"/>
        <vers num="0.9.8l"/>
        <vers num="0.9.8m"/>
        <vers num="0.9.8n"/>
        <vers num="0.9.8o"/>
        <vers num="0.9.8p"/>
        <vers num="0.9.8q"/>
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.0.0" edition="beta2"/>
        <vers num="1.0.0" edition="beta3"/>
        <vers num="1.0.0" edition="beta4"/>
        <vers num="1.0.0" edition="beta5"/>
        <vers num="1.0.0a"/>
        <vers num="1.0.0b"/>
        <vers num="1.0.0c"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0015" published="2011-01-19" name="CVE-2011-0015" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog" source="CONFIRM" patch="1">https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog</ref>
      <ref url="http://blog.torproject.org/blog/tor-02129-released-security-patches" source="CONFIRM" patch="1">http://blog.torproject.org/blog/tor-02129-released-security-patches</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2011/msg00000.html" source="MLIST" patch="1">[or-announce] 20110117 Tor 0.2.1.29 is released (security patches)</ref>
      <ref url="https://trac.torproject.org/projects/tor/ticket/2324" source="CONFIRM">https://trac.torproject.org/projects/tor/ticket/2324</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0132" source="VUPEN" adv="1">ADV-2011-0132</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0131" source="VUPEN" adv="1">ADV-2011-0131</ref>
      <ref url="http://www.securitytracker.com/id?1024980" source="SECTRACK">1024980</ref>
      <ref url="http://www.securityfocus.com/bid/45832" source="BID">45832</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/18/7" source="MLIST">[oss-security] 20110118 Re: CVE request: tor</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2148" source="DEBIAN">DSA-2148</ref>
      <ref url="http://secunia.com/advisories/42907" source="SECUNIA" adv="1">42907</ref>
      <ref url="http://secunia.com/advisories/42905" source="SECUNIA" adv="1">42905</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2"/>
        <vers num="0.0.2_pre13"/>
        <vers num="0.0.2_pre14"/>
        <vers num="0.0.2_pre15"/>
        <vers num="0.0.2_pre16"/>
        <vers num="0.0.2_pre17"/>
        <vers num="0.0.2_pre18"/>
        <vers num="0.0.2_pre19"/>
        <vers num="0.0.2_pre20"/>
        <vers num="0.0.2_pre21"/>
        <vers num="0.0.2_pre22"/>
        <vers num="0.0.2_pre23"/>
        <vers num="0.0.2_pre24"/>
        <vers num="0.0.2_pre25"/>
        <vers num="0.0.2_pre26"/>
        <vers num="0.0.2_pre27"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.6.1"/>
        <vers num="0.0.6.2"/>
        <vers num="0.0.7"/>
        <vers num="0.0.7.1"/>
        <vers num="0.0.7.2"/>
        <vers num="0.0.7.3"/>
        <vers num="0.0.8"/>
        <vers num="0.0.8.1"/>
        <vers num="0.0.9"/>
        <vers num="0.0.9.1"/>
        <vers num="0.0.9.10"/>
        <vers num="0.0.9.2"/>
        <vers num="0.0.9.3"/>
        <vers num="0.0.9.4"/>
        <vers num="0.0.9.5"/>
        <vers num="0.0.9.6"/>
        <vers num="0.0.9.7"/>
        <vers num="0.0.9.8"/>
        <vers num="0.0.9.9"/>
        <vers num="0.1.0.1"/>
        <vers num="0.1.0.10"/>
        <vers num="0.1.0.11"/>
        <vers num="0.1.0.12"/>
        <vers num="0.1.0.13"/>
        <vers num="0.1.0.14"/>
        <vers num="0.1.0.15"/>
        <vers num="0.1.0.16"/>
        <vers num="0.1.0.17"/>
        <vers num="0.1.0.2"/>
        <vers num="0.1.0.3"/>
        <vers num="0.1.0.4"/>
        <vers num="0.1.0.5"/>
        <vers num="0.1.0.6"/>
        <vers num="0.1.0.7"/>
        <vers num="0.1.0.8"/>
        <vers num="0.1.0.9"/>
        <vers num="0.1.1"/>
        <vers num="0.1.1.1" edition="alpha"/>
        <vers num="0.1.1.10" edition="alpha"/>
        <vers num="0.1.1.11"/>
        <vers num="0.1.1.12"/>
        <vers num="0.1.1.13"/>
        <vers num="0.1.1.14"/>
        <vers num="0.1.1.15"/>
        <vers num="0.1.1.16"/>
        <vers num="0.1.1.17"/>
        <vers num="0.1.1.18"/>
        <vers num="0.1.1.19"/>
        <vers num="0.1.1.2" edition="alpha"/>
        <vers num="0.1.1.20"/>
        <vers num="0.1.1.21"/>
        <vers num="0.1.1.22"/>
        <vers num="0.1.1.23"/>
        <vers num="0.1.1.25"/>
        <vers num="0.1.1.26"/>
        <vers num="0.1.1.3" edition="alpha"/>
        <vers num="0.1.1.4" edition="alpha"/>
        <vers num="0.1.1.5" edition="alpha"/>
        <vers num="0.1.1.6" edition="alpha"/>
        <vers num="0.1.1.7" edition="alpha"/>
        <vers num="0.1.1.8" edition="alpha"/>
        <vers num="0.1.1.9" edition="alpha"/>
        <vers num="0.1.2.1" edition="alpha-cvs"/>
        <vers num="0.1.2.10"/>
        <vers num="0.1.2.11"/>
        <vers num="0.1.2.12"/>
        <vers num="0.1.2.13"/>
        <vers num="0.1.2.14"/>
        <vers num="0.1.2.15"/>
        <vers num="0.1.2.16"/>
        <vers num="0.1.2.17"/>
        <vers num="0.1.2.18"/>
        <vers num="0.1.2.19"/>
        <vers num="0.1.2.2"/>
        <vers num="0.1.2.3" edition="alpha"/>
        <vers num="0.1.2.30"/>
        <vers num="0.1.2.31"/>
        <vers num="0.1.2.4"/>
        <vers num="0.1.2.5" edition="alpha"/>
        <vers num="0.1.2.6" edition="alpha"/>
        <vers num="0.1.2.7" edition="alpha"/>
        <vers num="0.1.2.8" edition="beta"/>
        <vers num="0.1.2.9"/>
        <vers num="0.2.0.1" edition="alpha"/>
        <vers num="0.2.0.10" edition="alpha"/>
        <vers num="0.2.0.11" edition="alpha"/>
        <vers num="0.2.0.12" edition="alpha"/>
        <vers num="0.2.0.13" edition="alpha"/>
        <vers num="0.2.0.14" edition="alpha"/>
        <vers num="0.2.0.15" edition="alpha"/>
        <vers num="0.2.0.16" edition="alpha"/>
        <vers num="0.2.0.17" edition="alpha"/>
        <vers num="0.2.0.18" edition="alpha"/>
        <vers num="0.2.0.19" edition="alpha"/>
        <vers num="0.2.0.2" edition="alpha"/>
        <vers num="0.2.0.20" edition="alpha"/>
        <vers num="0.2.0.21" edition="alpha"/>
        <vers num="0.2.0.22" edition="alpha"/>
        <vers num="0.2.0.23" edition="alpha"/>
        <vers num="0.2.0.24" edition="alpha"/>
        <vers num="0.2.0.25" edition="alpha"/>
        <vers num="0.2.0.26" edition="alpha"/>
        <vers num="0.2.0.27" edition="alpha"/>
        <vers num="0.2.0.28" edition="alpha"/>
        <vers num="0.2.0.29" edition="alpha"/>
        <vers num="0.2.0.3" edition="alpha"/>
        <vers num="0.2.0.30" edition="alpha"/>
        <vers num="0.2.0.31" edition="alpha"/>
        <vers num="0.2.0.32" edition="alpha"/>
        <vers num="0.2.0.33"/>
        <vers num="0.2.0.34" edition="alpha"/>
        <vers num="0.2.0.35"/>
        <vers num="0.2.0.4" edition="alpha"/>
        <vers num="0.2.0.5" edition="alpha"/>
        <vers num="0.2.0.6" edition="alpha"/>
        <vers num="0.2.0.7" edition="alpha"/>
        <vers num="0.2.0.8" edition="alpha"/>
        <vers num="0.2.0.9" edition="alpha"/>
        <vers num="0.2.1.1" edition="alpha"/>
        <vers num="0.2.1.10" edition="alpha"/>
        <vers num="0.2.1.11" edition="alpha"/>
        <vers num="0.2.1.12" edition="alpha"/>
        <vers num="0.2.1.13"/>
        <vers num="0.2.1.14"/>
        <vers num="0.2.1.15"/>
        <vers num="0.2.1.16"/>
        <vers num="0.2.1.17"/>
        <vers num="0.2.1.18"/>
        <vers num="0.2.1.19"/>
        <vers num="0.2.1.2" edition="alpha"/>
        <vers num="0.2.1.20"/>
        <vers num="0.2.1.21"/>
        <vers num="0.2.1.22"/>
        <vers num="0.2.1.23"/>
        <vers num="0.2.1.24"/>
        <vers num="0.2.1.25"/>
        <vers num="0.2.1.26"/>
        <vers num="0.2.1.27"/>
        <vers prev="1" num="0.2.1.28"/>
        <vers num="0.2.1.3" edition="alpha"/>
        <vers num="0.2.1.4" edition="alpha"/>
        <vers num="0.2.1.5" edition="alpha"/>
        <vers num="0.2.1.6" edition="alpha"/>
        <vers num="0.2.1.7" edition="alpha"/>
        <vers num="0.2.1.8" edition="alpha"/>
        <vers num="0.2.1.9" edition="alpha"/>
        <vers num="0.2.2.1" edition="alpha"/>
        <vers num="0.2.2.10" edition="alpha"/>
        <vers num="0.2.2.11" edition="alpha"/>
        <vers num="0.2.2.12" edition="alpha"/>
        <vers num="0.2.2.13" edition="alpha"/>
        <vers num="0.2.2.14" edition="alpha"/>
        <vers num="0.2.2.15" edition="alpha"/>
        <vers num="0.2.2.16" edition="alpha"/>
        <vers num="0.2.2.17" edition="alpha"/>
        <vers num="0.2.2.18" edition="alpha"/>
        <vers num="0.2.2.19" edition="alpha"/>
        <vers num="0.2.2.2" edition="alpha"/>
        <vers num="0.2.2.20" edition="alpha"/>
        <vers num="0.2.2.3" edition="alpha"/>
        <vers num="0.2.2.4" edition="alpha"/>
        <vers num="0.2.2.5" edition="alpha"/>
        <vers num="0.2.2.6" edition="alpha"/>
        <vers num="0.2.2.7" edition="alpha"/>
        <vers num="0.2.2.8" edition="alpha"/>
        <vers num="0.2.2.9" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0016" published="2011-01-19" name="CVE-2011-0016" modified="2011-01-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://blog.torproject.org/blog/tor-02129-released-security-patches" source="CONFIRM" patch="1" adv="1">http://blog.torproject.org/blog/tor-02129-released-security-patches</ref>
      <ref url="https://trac.torproject.org/projects/tor/ticket/2385" source="CONFIRM">https://trac.torproject.org/projects/tor/ticket/2385</ref>
      <ref url="https://trac.torproject.org/projects/tor/ticket/2384" source="CONFIRM">https://trac.torproject.org/projects/tor/ticket/2384</ref>
      <ref url="https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog" source="CONFIRM">https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0132" source="VUPEN" adv="1">ADV-2011-0132</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0131" source="VUPEN" adv="1">ADV-2011-0131</ref>
      <ref url="http://www.securitytracker.com/id?1024980" source="SECTRACK">1024980</ref>
      <ref url="http://www.securityfocus.com/bid/45832" source="BID">45832</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2011/01/18/7" source="MLIST">[oss-security] 20110118 Re: CVE request: tor</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2148" source="DEBIAN">DSA-2148</ref>
      <ref url="http://secunia.com/advisories/42907" source="SECUNIA" adv="1">42907</ref>
      <ref url="http://secunia.com/advisories/42905" source="SECUNIA" adv="1">42905</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2011/msg00000.html" source="MLIST">[or-announce] 20110117 Tor 0.2.1.29 is released (security patches)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2"/>
        <vers num="0.0.2_pre13"/>
        <vers num="0.0.2_pre14"/>
        <vers num="0.0.2_pre15"/>
        <vers num="0.0.2_pre16"/>
        <vers num="0.0.2_pre17"/>
        <vers num="0.0.2_pre18"/>
        <vers num="0.0.2_pre19"/>
        <vers num="0.0.2_pre20"/>
        <vers num="0.0.2_pre21"/>
        <vers num="0.0.2_pre22"/>
        <vers num="0.0.2_pre23"/>
        <vers num="0.0.2_pre24"/>
        <vers num="0.0.2_pre25"/>
        <vers num="0.0.2_pre26"/>
        <vers num="0.0.2_pre27"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.6.1"/>
        <vers num="0.0.6.2"/>
        <vers num="0.0.7"/>
        <vers num="0.0.7.1"/>
        <vers num="0.0.7.2"/>
        <vers num="0.0.7.3"/>
        <vers num="0.0.8"/>
        <vers num="0.0.8.1"/>
        <vers num="0.0.9"/>
        <vers num="0.0.9.1"/>
        <vers num="0.0.9.10"/>
        <vers num="0.0.9.2"/>
        <vers num="0.0.9.3"/>
        <vers num="0.0.9.4"/>
        <vers num="0.0.9.5"/>
        <vers num="0.0.9.6"/>
        <vers num="0.0.9.7"/>
        <vers num="0.0.9.8"/>
        <vers num="0.0.9.9"/>
        <vers num="0.1.0.1"/>
        <vers num="0.1.0.10"/>
        <vers num="0.1.0.11"/>
        <vers num="0.1.0.12"/>
        <vers num="0.1.0.13"/>
        <vers num="0.1.0.14"/>
        <vers num="0.1.0.15"/>
        <vers num="0.1.0.16"/>
        <vers num="0.1.0.17"/>
        <vers num="0.1.0.2"/>
        <vers num="0.1.0.3"/>
        <vers num="0.1.0.4"/>
        <vers num="0.1.0.5"/>
        <vers num="0.1.0.6"/>
        <vers num="0.1.0.7"/>
        <vers num="0.1.0.8"/>
        <vers num="0.1.0.9"/>
        <vers num="0.1.1"/>
        <vers num="0.1.1.1" edition="alpha"/>
        <vers num="0.1.1.10" edition="alpha"/>
        <vers num="0.1.1.11"/>
        <vers num="0.1.1.12"/>
        <vers num="0.1.1.13"/>
        <vers num="0.1.1.14"/>
        <vers num="0.1.1.15"/>
        <vers num="0.1.1.16"/>
        <vers num="0.1.1.17"/>
        <vers num="0.1.1.18"/>
        <vers num="0.1.1.19"/>
        <vers num="0.1.1.2" edition="alpha"/>
        <vers num="0.1.1.20"/>
        <vers num="0.1.1.21"/>
        <vers num="0.1.1.22"/>
        <vers num="0.1.1.23"/>
        <vers num="0.1.1.25"/>
        <vers num="0.1.1.26"/>
        <vers num="0.1.1.3" edition="alpha"/>
        <vers num="0.1.1.4" edition="alpha"/>
        <vers num="0.1.1.5" edition="alpha"/>
        <vers num="0.1.1.6" edition="alpha"/>
        <vers num="0.1.1.7" edition="alpha"/>
        <vers num="0.1.1.8" edition="alpha"/>
        <vers num="0.1.1.9" edition="alpha"/>
        <vers num="0.1.2.1" edition="alpha-cvs"/>
        <vers num="0.1.2.10"/>
        <vers num="0.1.2.11"/>
        <vers num="0.1.2.12"/>
        <vers num="0.1.2.13"/>
        <vers num="0.1.2.14"/>
        <vers num="0.1.2.15"/>
        <vers num="0.1.2.16"/>
        <vers num="0.1.2.17"/>
        <vers num="0.1.2.18"/>
        <vers num="0.1.2.19"/>
        <vers num="0.1.2.2"/>
        <vers num="0.1.2.3" edition="alpha"/>
        <vers num="0.1.2.30"/>
        <vers num="0.1.2.31"/>
        <vers num="0.1.2.4"/>
        <vers num="0.1.2.5" edition="alpha"/>
        <vers num="0.1.2.6" edition="alpha"/>
        <vers num="0.1.2.7" edition="alpha"/>
        <vers num="0.1.2.8" edition="beta"/>
        <vers num="0.1.2.9"/>
        <vers num="0.2.0.1" edition="alpha"/>
        <vers num="0.2.0.10" edition="alpha"/>
        <vers num="0.2.0.11" edition="alpha"/>
        <vers num="0.2.0.12" edition="alpha"/>
        <vers num="0.2.0.13" edition="alpha"/>
        <vers num="0.2.0.14" edition="alpha"/>
        <vers num="0.2.0.15" edition="alpha"/>
        <vers num="0.2.0.16" edition="alpha"/>
        <vers num="0.2.0.17" edition="alpha"/>
        <vers num="0.2.0.18" edition="alpha"/>
        <vers num="0.2.0.19" edition="alpha"/>
        <vers num="0.2.0.2" edition="alpha"/>
        <vers num="0.2.0.20" edition="alpha"/>
        <vers num="0.2.0.21" edition="alpha"/>
        <vers num="0.2.0.22" edition="alpha"/>
        <vers num="0.2.0.23" edition="alpha"/>
        <vers num="0.2.0.24" edition="alpha"/>
        <vers num="0.2.0.25" edition="alpha"/>
        <vers num="0.2.0.26" edition="alpha"/>
        <vers num="0.2.0.27" edition="alpha"/>
        <vers num="0.2.0.28" edition="alpha"/>
        <vers num="0.2.0.29" edition="alpha"/>
        <vers num="0.2.0.3" edition="alpha"/>
        <vers num="0.2.0.30" edition="alpha"/>
        <vers num="0.2.0.31" edition="alpha"/>
        <vers num="0.2.0.32" edition="alpha"/>
        <vers num="0.2.0.33"/>
        <vers num="0.2.0.34" edition="alpha"/>
        <vers num="0.2.0.35"/>
        <vers num="0.2.0.4" edition="alpha"/>
        <vers num="0.2.0.5" edition="alpha"/>
        <vers num="0.2.0.6" edition="alpha"/>
        <vers num="0.2.0.7" edition="alpha"/>
        <vers num="0.2.0.8" edition="alpha"/>
        <vers num="0.2.0.9" edition="alpha"/>
        <vers num="0.2.1.1" edition="alpha"/>
        <vers num="0.2.1.10" edition="alpha"/>
        <vers num="0.2.1.11" edition="alpha"/>
        <vers num="0.2.1.12" edition="alpha"/>
        <vers num="0.2.1.13"/>
        <vers num="0.2.1.14"/>
        <vers num="0.2.1.15"/>
        <vers num="0.2.1.16"/>
        <vers num="0.2.1.17"/>
        <vers num="0.2.1.18"/>
        <vers num="0.2.1.19"/>
        <vers num="0.2.1.2" edition="alpha"/>
        <vers num="0.2.1.20"/>
        <vers num="0.2.1.21"/>
        <vers num="0.2.1.22"/>
        <vers num="0.2.1.23"/>
        <vers num="0.2.1.24"/>
        <vers num="0.2.1.25"/>
        <vers num="0.2.1.26"/>
        <vers num="0.2.1.27"/>
        <vers prev="1" num="0.2.1.28"/>
        <vers num="0.2.1.3" edition="alpha"/>
        <vers num="0.2.1.4" edition="alpha"/>
        <vers num="0.2.1.5" edition="alpha"/>
        <vers num="0.2.1.6" edition="alpha"/>
        <vers num="0.2.1.7" edition="alpha"/>
        <vers num="0.2.1.8" edition="alpha"/>
        <vers num="0.2.1.9" edition="alpha"/>
        <vers num="0.2.2.1" edition="alpha"/>
        <vers num="0.2.2.10" edition="alpha"/>
        <vers num="0.2.2.11" edition="alpha"/>
        <vers num="0.2.2.12" edition="alpha"/>
        <vers num="0.2.2.13" edition="alpha"/>
        <vers num="0.2.2.14" edition="alpha"/>
        <vers num="0.2.2.15" edition="alpha"/>
        <vers num="0.2.2.16" edition="alpha"/>
        <vers num="0.2.2.17" edition="alpha"/>
        <vers num="0.2.2.18" edition="alpha"/>
        <vers num="0.2.2.19" edition="alpha"/>
        <vers num="0.2.2.2" edition="alpha"/>
        <vers num="0.2.2.20" edition="alpha"/>
        <vers num="0.2.2.3" edition="alpha"/>
        <vers num="0.2.2.4" edition="alpha"/>
        <vers num="0.2.2.5" edition="alpha"/>
        <vers num="0.2.2.6" edition="alpha"/>
        <vers num="0.2.2.7" edition="alpha"/>
        <vers num="0.2.2.8" edition="alpha"/>
        <vers num="0.2.2.9" edition="alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0017" published="2011-02-01" name="CVE-2011-0017" modified="2011-03-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The open_log function in log.c in Exim 4.72 and earlier does not check the return value from (1) setuid or (2) setgid system calls, which allows local users to append log data to arbitrary files via a symlink attack.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://lists.exim.org/lurker/message/20110126.034702.4d69c278.en.html" source="MLIST" patch="1">[exim-announce] 20110125 Exim 4.74 Release</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65028" source="XF">exim-openlog-privilege-escalation(65028)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0464" source="VUPEN">ADV-2011-0464</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0364" source="VUPEN">ADV-2011-0364</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0245" source="VUPEN" adv="1">ADV-2011-0245</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0224" source="VUPEN" adv="1">ADV-2011-0224</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1060-1" source="UBUNTU">USN-1060-1</ref>
      <ref url="http://www.securityfocus.com/bid/46065" source="BID">46065</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2154" source="DEBIAN">DSA-2154</ref>
      <ref url="http://secunia.com/advisories/43243" source="SECUNIA">43243</ref>
      <ref url="http://secunia.com/advisories/43128" source="SECUNIA" adv="1">43128</ref>
      <ref url="http://secunia.com/advisories/43101" source="SECUNIA" adv="1">43101</ref>
      <ref url="http://osvdb.org/70696" source="OSVDB">70696</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html" source="SUSE">SUSE-SR:2011:004</ref>
      <ref url="ftp://ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.74" source="CONFIRM">ftp://ftp.exim.org/pub/exim/ChangeLogs/ChangeLog-4.74</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exim" name="exim">
        <vers num="2.10"/>
        <vers num="2.11"/>
        <vers num="2.12"/>
        <vers num="3.00"/>
        <vers num="3.01"/>
        <vers num="3.02"/>
        <vers num="3.03"/>
        <vers num="3.10"/>
        <vers num="3.11"/>
        <vers num="3.12"/>
        <vers num="3.13"/>
        <vers num="3.14"/>
        <vers num="3.15"/>
        <vers num="3.16"/>
        <vers num="3.20"/>
        <vers num="3.21"/>
        <vers num="3.22"/>
        <vers num="3.30"/>
        <vers num="3.31"/>
        <vers num="3.32"/>
        <vers num="3.33"/>
        <vers num="3.34"/>
        <vers num="3.35"/>
        <vers num="3.36"/>
        <vers num="4.00"/>
        <vers num="4.01"/>
        <vers num="4.02"/>
        <vers num="4.03"/>
        <vers num="4.04"/>
        <vers num="4.05"/>
        <vers num="4.10"/>
        <vers num="4.11"/>
        <vers num="4.12"/>
        <vers num="4.14"/>
        <vers num="4.20"/>
        <vers num="4.21"/>
        <vers num="4.22"/>
        <vers num="4.23"/>
        <vers num="4.24"/>
        <vers num="4.30"/>
        <vers num="4.31"/>
        <vers num="4.32"/>
        <vers num="4.33"/>
        <vers num="4.34"/>
        <vers num="4.40"/>
        <vers num="4.41"/>
        <vers num="4.42"/>
        <vers num="4.43"/>
        <vers num="4.44"/>
        <vers num="4.50"/>
        <vers num="4.51"/>
        <vers num="4.52"/>
        <vers num="4.53"/>
        <vers num="4.54"/>
        <vers num="4.60"/>
        <vers num="4.61"/>
        <vers num="4.62"/>
        <vers num="4.63"/>
        <vers num="4.64"/>
        <vers num="4.65"/>
        <vers num="4.66"/>
        <vers num="4.67"/>
        <vers num="4.68"/>
        <vers num="4.69"/>
        <vers num="4.70"/>
        <vers num="4.71"/>
        <vers prev="1" num="4.72"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0018" published="2011-01-28" name="CVE-2011-0018" modified="2011-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.openvas.org/OVSA20110118.html" source="CONFIRM" patch="1" adv="1">http://www.openvas.org/OVSA20110118.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65011" source="XF">openvas-email-command-execution(65011)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0208" source="VUPEN" adv="1">ADV-2011-0208</ref>
      <ref url="http://www.securityfocus.com/bid/45987" source="BID">45987</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515971/100/0/threaded" source="BUGTRAQ">20110125 [OVSA20110118] OpenVAS Manager Vulnerable To Command Injection</ref>
      <ref url="http://www.exploit-db.com/exploits/16086" source="EXPLOIT-DB">16086</ref>
      <ref url="http://secunia.com/advisories/43037" source="SECUNIA">43037</ref>
      <ref url="http://osvdb.org/70639" source="OSVDB">70639</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openvas" name="openvas_manager">
        <vers num="1.0.0" edition="beta1"/>
        <vers num="1.0.0" edition="beta2"/>
        <vers num="1.0.0" edition="beta3"/>
        <vers num="1.0.0" edition="beta4"/>
        <vers num="1.0.0" edition="beta5"/>
        <vers num="1.0.0" edition="beta6"/>
        <vers num="1.0.0" edition="beta7"/>
        <vers num="1.0.0" edition="rc1"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="2.0" edition="beta1"/>
        <vers num="2.0" edition="beta2"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0019" published="2011-02-23" name="CVE-2011-0019" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">slapd (aka ns-slapd) in 389 Directory Server 1.2.7.5 (aka Red Hat Directory Server 8.2.x or dirsrv) does not properly handle simple paged result searches, which allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via multiple search requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=670914" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=670914</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=666076" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=666076</ref>
      <ref url="http://www.securitytracker.com/id?1025102" source="SECTRACK">1025102</ref>
      <ref url="http://www.securityfocus.com/bid/46489" source="BID">46489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0293.html" source="REDHAT">RHSA-2011:0293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="389_directory_server">
        <vers num="1.2.7.5"/>
      </prod>
      <prod vendor="redhat" name="directory_server">
        <vers num="8.2"/>
        <vers num="8.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0020" published="2011-01-24" name="CVE-2011-0020" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=671122" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=671122</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=639882" source="MISC">https://bugzilla.gnome.org/show_bug.cgi?id=639882</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/pango1.0/+bug/696616</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64832" source="XF">pango-pango-bo(64832)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0238" source="VUPEN">ADV-2011-0238</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0186" source="VUPEN" adv="1">ADV-2011-0186</ref>
      <ref url="http://www.securitytracker.com/id?1024994" source="SECTRACK">1024994</ref>
      <ref url="http://www.securityfocus.com/bid/45842" source="BID">45842</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0180.html" source="REDHAT">RHSA-2011:0180</ref>
      <ref url="http://secunia.com/advisories/43100" source="SECUNIA">43100</ref>
      <ref url="http://secunia.com/advisories/42934" source="SECUNIA">42934</ref>
      <ref url="http://osvdb.org/70596" source="OSVDB">70596</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/20/2" source="MLIST">[oss-security] 20110120 Re: CVE request: heap corruption in libpango</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/18/6" source="MLIST">[oss-security] 20110118 CVE request: heap corruption in libpango</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pango" name="pango">
        <vers num="0.20"/>
        <vers num="0.21"/>
        <vers num="0.22"/>
        <vers num="0.23"/>
        <vers num="0.24"/>
        <vers num="0.25"/>
        <vers num="0.26"/>
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.10"/>
        <vers num="1.11"/>
        <vers num="1.12"/>
        <vers num="1.13"/>
        <vers num="1.14"/>
        <vers num="1.15"/>
        <vers num="1.16"/>
        <vers num="1.17"/>
        <vers num="1.18"/>
        <vers num="1.19"/>
        <vers num="1.2"/>
        <vers num="1.20"/>
        <vers num="1.21"/>
        <vers num="1.22"/>
        <vers num="1.23"/>
        <vers num="1.24"/>
        <vers num="1.25"/>
        <vers num="1.26"/>
        <vers num="1.27"/>
        <vers num="1.28.0"/>
        <vers num="1.28.1"/>
        <vers num="1.28.2"/>
        <vers prev="1" num="1.28.3"/>
        <vers num="1.3"/>
        <vers num="1.4"/>
        <vers num="1.5"/>
        <vers num="1.6"/>
        <vers num="1.7"/>
        <vers num="1.8"/>
        <vers num="1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0021" published="2011-01-25" name="CVE-2011-0021" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in cdg.c in the CDG decoder in VideoLAN VLC Media Player before 1.1.6 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted CDG video.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2011/01/20/3" source="MLIST" patch="1">[oss-security] 20110120 Re: CVE request: heap corruption in VLC media player</ref>
      <ref url="http://git.videolan.org/?p=vlc.git;a=commit;h=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aab" source="CONFIRM" patch="1">http://git.videolan.org/?p=vlc.git;a=commit;h=f9b664eac0e1a7bceed9d7b5854fd9fc351b4aab</ref>
      <ref url="http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2" source="CONFIRM" patch="1">http://download.videolan.org/pub/videolan/vlc/1.1.6/vlc-1.1.6.tar.bz2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64879" source="XF">vlcmediaplayer-cdg-code-execution(64879)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0185" source="VUPEN" adv="1">ADV-2011-0185</ref>
      <ref url="http://www.securityfocus.com/bid/45927" source="BID">45927</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12460" source="OVAL">oval:org.mitre.oval:def:12460</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/01/19/6" source="MLIST">[oss-security] 20110119 CVE request: heap corruption in VLC media player</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.1.99b"/>
        <vers num="0.1.99e"/>
        <vers num="0.1.99f"/>
        <vers num="0.1.99g"/>
        <vers num="0.1.99h"/>
        <vers num="0.1.99i"/>
        <vers num="0.2.0"/>
        <vers num="0.2.60"/>
        <vers num="0.2.61"/>
        <vers num="0.2.62"/>
        <vers num="0.2.63"/>
        <vers num="0.2.70"/>
        <vers num="0.2.71"/>
        <vers num="0.2.72"/>
        <vers num="0.2.73"/>
        <vers num="0.2.80"/>
        <vers num="0.2.81"/>
        <vers num="0.2.82"/>
        <vers num="0.2.83"/>
        <vers num="0.2.90"/>
        <vers num="0.2.91"/>
        <vers num="0.2.92"/>
        <vers num="0.3.0"/>
        <vers num="0.3.1"/>
        <vers num="0.4.0"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="0.4.4"/>
        <vers num="0.4.5"/>
        <vers num="0.4.6"/>
        <vers num="0.5.0"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers num="0.5.3"/>
        <vers num="0.6.0"/>
        <vers num="0.6.1"/>
        <vers num="0.6.2"/>
        <vers num="0.7.0"/>
        <vers num="0.7.2"/>
        <vers num="0.8.0"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.4"/>
        <vers num="0.8.5"/>
        <vers num="0.8.6"/>
        <vers num="0.9.10"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.8a"/>
        <vers num="0.9.9"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers prev="1" num="1.1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0022" published="2011-02-23" name="CVE-2011-0022" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The setup scripts in 389 Directory Server 1.2.x (aka Red Hat Directory Server 8.2.x), when multiple unprivileged instances are configured, use 0777 permissions for the /var/run/dirsrv directory, which allows local users to cause a denial of service (daemon outage or arbitrary process termination) by replacing PID files contained in this directory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=671199" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=671199</ref>
      <ref url="http://www.securitytracker.com/id?1025102" source="SECTRACK">1025102</ref>
      <ref url="http://www.securityfocus.com/bid/46489" source="BID">46489</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0293.html" source="REDHAT">RHSA-2011:0293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fedoraproject" name="389_directory_server">
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.5" edition="rc1"/>
        <vers num="1.2.5" edition="rc2"/>
        <vers num="1.2.5" edition="rc3"/>
        <vers num="1.2.5" edition="rc4"/>
        <vers num="1.2.6" edition="a2"/>
        <vers num="1.2.6" edition="a3"/>
        <vers num="1.2.6" edition="a4"/>
        <vers num="1.2.6" edition="rc1"/>
        <vers num="1.2.6" edition="rc2"/>
        <vers num="1.2.6" edition="rc3"/>
        <vers num="1.2.6" edition="rc6"/>
        <vers num="1.2.6" edition="rc7"/>
        <vers num="1.2.6.1"/>
        <vers num="1.2.7" edition="alpha3"/>
        <vers num="1.2.7.5"/>
        <vers num="1.2.8" edition="alpha1"/>
        <vers num="1.2.8" edition="alpha2"/>
      </prod>
      <prod vendor="redhat" name="directory_server">
        <vers num="8.2"/>
        <vers num="8.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0024" published="2011-03-28" name="CVE-2011-0024" modified="2011-03-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=671331" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=671331</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0719" source="VUPEN" adv="1">ADV-2011-0719</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0370.html" source="REDHAT">RHSA-2011:0370</ref>
      <ref url="http://secunia.com/advisories/43821" source="SECUNIA" adv="1">43821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.2"/>
        <vers num="0.99.3"/>
        <vers num="0.99.4"/>
        <vers num="0.99.5"/>
        <vers num="0.99.6"/>
        <vers num="0.99.7"/>
        <vers num="0.99.8"/>
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.13"/>
        <vers num="1.0.14"/>
        <vers num="1.0.15"/>
        <vers prev="1" num="1.0.16"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0025" published="2011-02-04" name="CVE-2011-0025" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset;node=3bd328e4b515" source="MISC" patch="1">http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset;node=3bd328e4b515</ref>
      <ref url="http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/" source="CONFIRM" patch="1">http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65151" source="XF">icedtea-jar-security-bypass(65151)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1055-1" source="UBUNTU">USN-1055-1</ref>
      <ref url="http://www.securityfocus.com/bid/46110" source="BID">46110</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:054" source="MANDRIVA">MDVSA-2011:054</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2224" source="DEBIAN">DSA-2224</ref>
      <ref url="http://secunia.com/advisories/43135" source="SECUNIA" adv="1">43135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="icedtea">
        <vers num="1.7"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.7.4"/>
        <vers num="1.7.5"/>
        <vers num="1.7.6"/>
        <vers num="1.7.7"/>
        <vers num="1.8"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.9"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0026" published="2011-01-11" name="CVE-2011-0026" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-011A.html" source="CERT">TA11-011A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-002.mspx" source="MS" patch="1" adv="1">MS11-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-001/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-001/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0075" source="VUPEN">ADV-2011-0075</ref>
      <ref url="http://www.securitytracker.com/id?1024947" source="SECTRACK">1024947</ref>
      <ref url="http://www.securityfocus.com/bid/45695" source="BID">45695</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100124846" source="CONFIRM">http://support.avaya.com/css/P8/documents/100124846</ref>
      <ref url="http://secunia.com/advisories/42804" source="SECUNIA">42804</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12333" source="OVAL">oval:org.mitre.oval:def:12333</ref>
      <ref url="http://osvdb.org/70443" source="OSVDB">70443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="2.8" edition="sp1"/>
        <vers num="2.8" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_data_access_components">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0027" published="2011-01-11" name="CVE-2011-0027" modified="2013-01-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability."  NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-011A.html" source="CERT">TA11-011A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-002.mspx" source="MS" patch="1" adv="1">MS11-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-002/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-002/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0075" source="VUPEN" adv="1">ADV-2011-0075</ref>
      <ref url="http://www.securitytracker.com/id?1024947" source="SECTRACK">1024947</ref>
      <ref url="http://www.securityfocus.com/bid/45698" source="BID">45698</ref>
      <ref url="http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/" source="MISC">http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100124846" source="CONFIRM">http://support.avaya.com/css/P8/documents/100124846</ref>
      <ref url="http://secunia.com/advisories/42804" source="SECUNIA" adv="1">42804</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12411" source="OVAL">oval:org.mitre.oval:def:12411</ref>
      <ref url="http://osvdb.org/70444" source="OSVDB">70444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="2.8" edition="sp1"/>
        <vers num="2.8" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_data_access_components">
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0028" published="2011-04-13" name="CVE-2011-0028" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-033.mspx" source="MS" patch="1" adv="1">MS11-033</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12301" source="OVAL">oval:org.mitre.oval:def:12301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0029" published="2011-03-09" name="CVE-2011-0029" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html
'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS11-017.mspx

'For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open an .rdp file.'

FAQ: 'This is a remote code execution vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" source="CERT">TA11-067A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-017.mspx" source="MS" patch="1" adv="1">MS11-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0616" source="VUPEN">ADV-2011-0616</ref>
      <ref url="http://www.securitytracker.com/id?1025172" source="SECTRACK">1025172</ref>
      <ref url="http://secunia.com/advisories/43628" source="SECUNIA">43628</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12480" source="OVAL">oval:org.mitre.oval:def:12480</ref>
      <ref url="http://osvdb.org/71014" source="OSVDB">71014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="remote_desktop_connection_client">
        <vers num="5.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0030" published="2011-02-08" name="CVE-2011-0030" modified="2013-02-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-010.mspx" source="MS" patch="1" adv="1">MS11-010</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64917" source="XF">ms-csrss-privilege-escalation(64917)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0323" source="VUPEN">ADV-2011-0323</ref>
      <ref url="http://www.securitytracker.com/id?1025045" source="SECTRACK">1025045</ref>
      <ref url="http://secunia.com/advisories/43250" source="SECUNIA" adv="1">43250</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12476" source="OVAL">oval:org.mitre.oval:def:12476</ref>
      <ref url="http://osvdb.org/70826" source="OSVDB">70826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0031" published="2011-02-08" name="CVE-2011-0031" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-009.mspx" source="MS" patch="1" adv="1">MS11-009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64919" source="XF">ms-win-jscript-info-disclosure(64919)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0322" source="VUPEN" adv="1">ADV-2011-0322</ref>
      <ref url="http://www.securitytracker.com/id?1025044" source="SECTRACK">1025044</ref>
      <ref url="http://www.securityfocus.com/bid/46139" source="BID">46139</ref>
      <ref url="http://secunia.com/advisories/43249" source="SECUNIA" adv="1">43249</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12313" source="OVAL">oval:org.mitre.oval:def:12313</ref>
      <ref url="http://osvdb.org/70827" source="OSVDB">70827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0032" published="2011-03-09" name="CVE-2011-0032" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html 
'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS11-015.mspx

'For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a media file (such as .wtv, .drv-ms, or .mpg files).'

FAQ: 'This is a remote code execution vulnerability. '</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" source="CERT">TA11-067A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-015.mspx" source="MS" patch="1" adv="1">MS11-015</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0615" source="VUPEN">ADV-2011-0615</ref>
      <ref url="http://www.securitytracker.com/id?1025170" source="SECTRACK">1025170</ref>
      <ref url="http://www.securityfocus.com/bid/46682" source="BID">46682</ref>
      <ref url="http://secunia.com/advisories/43626" source="SECUNIA">43626</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12506" source="OVAL">oval:org.mitre.oval:def:12506</ref>
      <ref url="http://osvdb.org/71015" source="OSVDB">71015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_center_tv_pack">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0033" published="2011-02-10" name="CVE-2011-0033" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-007.mspx" source="MS" patch="1" adv="1">MS11-007</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64906" source="XF">ms-opentype-cff-code-execution(64906)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0320" source="VUPEN" adv="1">ADV-2011-0320</ref>
      <ref url="http://www.securitytracker.com/id?1025034" source="SECTRACK">1025034</ref>
      <ref url="http://www.securityfocus.com/bid/46106" source="BID">46106</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127239" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127239</ref>
      <ref url="http://secunia.com/advisories/43252" source="SECUNIA" adv="1">43252</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11593" source="OVAL">oval:org.mitre.oval:def:11593</ref>
      <ref url="http://osvdb.org/70821" source="OSVDB">70821</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0034" published="2011-04-13" name="CVE-2011-0034" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-032.mspx" source="MS" patch="1" adv="1">MS11-032</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11860" source="OVAL">oval:org.mitre.oval:def:11860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
        <vers num="r2" edition="sp1"/>
        <vers num="r2" edition="sp1:x64"/>
        <vers num="r2" edition="sp1:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0035" published="2011-02-10" name="CVE-2011-0035" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0036.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" source="MS" patch="1" adv="1">MS11-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64911" source="XF">ms-explorer-code-execution(64911)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0318" source="VUPEN" adv="1">ADV-2011-0318</ref>
      <ref url="http://www.securitytracker.com/id?1025038" source="SECTRACK">1025038</ref>
      <ref url="http://www.securityfocus.com/bid/46157" source="BID">46157</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127294" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127294</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12371" source="OVAL">oval:org.mitre.oval:def:12371</ref>
      <ref url="http://osvdb.org/70831" source="OSVDB">70831</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0036" published="2011-02-10" name="CVE-2011-0036" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, relagted to a "dangling pointer," aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0035.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" source="MS" patch="1" adv="1">MS11-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64912" source="XF">ms-explorer-code-exec(64912)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0318" source="VUPEN" adv="1">ADV-2011-0318</ref>
      <ref url="http://www.securitytracker.com/id?1025038" source="SECTRACK">1025038</ref>
      <ref url="http://www.securityfocus.com/bid/46158" source="BID">46158</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127294" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127294</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12261" source="OVAL">oval:org.mitre.oval:def:12261</ref>
      <ref url="http://osvdb.org/70832" source="OSVDB">70832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0037" published="2011-02-25" name="CVE-2011-0037" modified="2011-04-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65626" source="XF">ms-malware-engine-priv-esc(65626)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0486" source="VUPEN" adv="1">ADV-2011-0486</ref>
      <ref url="http://www.securityfocus.com/bid/46540" source="BID">46540</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/2491888.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/2491888.mspx</ref>
      <ref url="http://securitytracker.com/id?1025117" source="SECTRACK">1025117</ref>
      <ref url="http://secunia.com/advisories/43468" source="SECUNIA" adv="1">43468</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_client_security">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="forefront_endpoint_protection_2010">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="malicious_software_removal_tool">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="malware_protection_engine">
        <vers num="0.1.13.192"/>
        <vers num="1.1.3520.0"/>
        <vers prev="1" num="1.1.6502.0"/>
      </prod>
      <prod vendor="microsoft" name="security_essentials">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_defender">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_live_onecare">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0038" published="2011-02-10" name="CVE-2011-0038" modified="2011-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain privileges via a Trojan horse IEShims.dll in the current working directory, as demonstrated by a Desktop directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."</descript>
      <descript source="nvd">Per: CWE-426: Untrusted Search Path

'http://cwe.mitre.org/data/definitions/426.html'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx

'This is a remote code execution vulnerability.'</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-003.mspx" source="MS" patch="1" adv="1">MS11-003</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64913" source="XF">ms-ie-dll-code-execution(64913)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0318" source="VUPEN" adv="1">ADV-2011-0318</ref>
      <ref url="http://www.securitytracker.com/id?1025038" source="SECTRACK">1025038</ref>
      <ref url="http://www.securityfocus.com/bid/46159" source="BID">46159</ref>
      <ref url="http://www.fortiguard.com/advisory/FGA-2011-04.html" source="MISC">http://www.fortiguard.com/advisory/FGA-2011-04.html</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127294" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127294</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12270" source="OVAL">oval:org.mitre.oval:def:12270</ref>
      <ref url="http://osvdb.org/70833" source="OSVDB">70833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0039" published="2011-02-08" name="CVE-2011-0039" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-014.mspx" source="MS" patch="1" adv="1">MS11-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0327" source="VUPEN" adv="1">ADV-2011-0327</ref>
      <ref url="http://www.securitytracker.com/id?1025049" source="SECTRACK">1025049</ref>
      <ref url="http://www.securityfocus.com/bid/46152" source="BID">46152</ref>
      <ref url="http://secunia.com/advisories/43253" source="SECUNIA" adv="1">43253</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12537" source="OVAL">oval:org.mitre.oval:def:12537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0040" published="2011-02-08" name="CVE-2011-0040" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-005.mspx" source="MS" patch="1" adv="1">MS11-005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64915" source="XF">ms-win-active-directory-dos(64915)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0319" source="VUPEN" adv="1">ADV-2011-0319</ref>
      <ref url="http://www.securitytracker.com/id?1025042" source="SECTRACK">1025042</ref>
      <ref url="http://www.securityfocus.com/bid/46145" source="BID">46145</ref>
      <ref url="http://secunia.com/advisories/43215" source="SECUNIA" adv="1">43215</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12485" source="OVAL">oval:org.mitre.oval:def:12485</ref>
      <ref url="http://osvdb.org/70825" source="OSVDB">70825</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0041" published="2011-04-13" name="CVE-2011-0041" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-029.mspx" source="MS" patch="1" adv="1">MS11-029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11854" source="OVAL">oval:org.mitre.oval:def:11854</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0042" published="2011-03-09" name="CVE-2011-0042" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-067A.html" source="CERT">TA11-067A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-015.mspx" source="MS" patch="1" adv="1">MS11-015</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0615" source="VUPEN">ADV-2011-0615</ref>
      <ref url="http://www.securitytracker.com/id?1025169" source="SECTRACK">1025169</ref>
      <ref url="http://www.securityfocus.com/bid/46680" source="BID">46680</ref>
      <ref url="http://secunia.com/advisories/43626" source="SECUNIA">43626</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12281" source="OVAL">oval:org.mitre.oval:def:12281</ref>
      <ref url="http://osvdb.org/71016" source="OSVDB">71016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_center_tv_pack">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp_media_center">
        <vers num="2005" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
        <vers num="-" edition="sp1"/>
        <vers num="-" edition="sp1:x64"/>
        <vers num="-" edition="sp1:x32"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0043" published="2011-02-10" name="CVE-2011-0043" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-013.mspx" source="MS" patch="1" adv="1">MS11-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64900" source="XF">ms-kerberos-checksum-privilege-escalation(64900)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0326" source="VUPEN" adv="1">ADV-2011-0326</ref>
      <ref url="http://www.securitytracker.com/id?1025048" source="SECTRACK">1025048</ref>
      <ref url="http://www.securityfocus.com/bid/46130" source="BID">46130</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127250" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127250</ref>
      <ref url="http://secunia.com/advisories/43251" source="SECUNIA" adv="1">43251</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12432" source="OVAL">oval:org.mitre.oval:def:12432</ref>
      <ref url="http://osvdb.org/70834" source="OSVDB">70834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0045" published="2011-02-08" name="CVE-2011-0045" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka "Windows Kernel Integer Truncation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-011.mspx" source="MS" patch="1" adv="1">MS11-011</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64926" source="XF">ms-win-kernel-privilege-escalation(64926)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-064" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-064</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0324" source="VUPEN" adv="1">ADV-2011-0324</ref>
      <ref url="http://www.securitytracker.com/id?1025046" source="SECTRACK">1025046</ref>
      <ref url="http://www.securityfocus.com/bid/46136" source="BID">46136</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516276/100/0/threaded" source="BUGTRAQ">20110208 ZDI-11-064: Microsoft Windows WmiTraceMessageVa Local Kernel Vulnerability</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127248" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127248</ref>
      <ref url="http://securityreason.com/securityalert/8110" source="SREASON">8110</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11996" source="OVAL">oval:org.mitre.oval:def:11996</ref>
      <ref url="http://osvdb.org/70823" source="OSVDB">70823</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0046" published="2011-01-28" name="CVE-2011-0046" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests related to (1) adding a saved search in buglist.cgi, (2) voting in votes.cgi, (3) sanity checking in sanitycheck.cgi, (4) creating or editing a chart in chart.cgi, (5) column changing in colchange.cgi, and (6) adding, deleting, or approving a quip in quips.cgi.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621110" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621110</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621109" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621109</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621108" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621108</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621107" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621107</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621105" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621105</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=621090" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=621090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65003" source="XF">bugzilla-unspec-csrf(65003)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0271" source="VUPEN">ADV-2011-0271</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0207" source="VUPEN" adv="1">ADV-2011-0207</ref>
      <ref url="http://www.securityfocus.com/bid/45982" source="BID">45982</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2322" source="DEBIAN">DSA-2322</ref>
      <ref url="http://www.bugzilla.org/security/3.2.9/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.2.9/</ref>
      <ref url="http://secunia.com/advisories/43165" source="SECUNIA">43165</ref>
      <ref url="http://secunia.com/advisories/43033" source="SECUNIA" adv="1">43033</ref>
      <ref url="http://osvdb.org/70710" source="OSVDB">70710</ref>
      <ref url="http://osvdb.org/70709" source="OSVDB">70709</ref>
      <ref url="http://osvdb.org/70708" source="OSVDB">70708</ref>
      <ref url="http://osvdb.org/70707" source="OSVDB">70707</ref>
      <ref url="http://osvdb.org/70706" source="OSVDB">70706</ref>
      <ref url="http://osvdb.org/70705" source="OSVDB">70705</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html" source="FEDORA">FEDORA-2011-0755</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html" source="FEDORA">FEDORA-2011-0741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.0"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16" edition="rc1"/>
        <vers num="2.16" edition="rc2"/>
        <vers num="2.16.1"/>
        <vers num="2.16.10"/>
        <vers num="2.16.11"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.16.4"/>
        <vers num="2.16.5"/>
        <vers num="2.16.6"/>
        <vers num="2.16.7"/>
        <vers num="2.16.8"/>
        <vers num="2.16.9"/>
        <vers num="2.16_rc2"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
        <vers num="2.17.2"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
        <vers num="2.17.5"/>
        <vers num="2.17.6"/>
        <vers num="2.17.7"/>
        <vers num="2.18" edition="rc1"/>
        <vers num="2.18" edition="rc2"/>
        <vers num="2.18" edition="rc3"/>
        <vers num="2.18.1"/>
        <vers num="2.18.2"/>
        <vers num="2.18.3"/>
        <vers num="2.18.4"/>
        <vers num="2.18.5"/>
        <vers num="2.18.6"/>
        <vers num="2.18.6+"/>
        <vers num="2.18.7"/>
        <vers num="2.18.8"/>
        <vers num="2.18.9"/>
        <vers num="2.19"/>
        <vers num="2.19.1"/>
        <vers num="2.19.2"/>
        <vers num="2.19.3"/>
        <vers num="2.2"/>
        <vers num="2.20" edition="rc1"/>
        <vers num="2.20" edition="rc2"/>
        <vers num="2.20.1"/>
        <vers num="2.20.2"/>
        <vers num="2.20.3"/>
        <vers num="2.20.4"/>
        <vers num="2.20.5"/>
        <vers num="2.20.6"/>
        <vers num="2.20.7"/>
        <vers num="2.21"/>
        <vers num="2.21.1"/>
        <vers num="2.21.2"/>
        <vers num="2.22" edition="rc1"/>
        <vers num="2.22.1"/>
        <vers num="2.22.2"/>
        <vers num="2.22.3"/>
        <vers num="2.22.4"/>
        <vers num="2.22.5"/>
        <vers num="2.22.6"/>
        <vers num="2.22.7"/>
        <vers num="2.23"/>
        <vers num="2.23.1"/>
        <vers num="2.23.2"/>
        <vers num="2.23.3"/>
        <vers num="2.23.4"/>
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.2" edition="rc1"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers prev="1" num="3.2.9"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="4.0" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0047" published="2011-02-03" name="CVE-2011-0047" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2011-February/000095.html" source="MLIST" patch="1" adv="1">[MediaWiki-announce] 20110201 MediaWiki security release 1.16.2</ref>
      <ref url="https://bugzilla.wikimedia.org/show_bug.cgi?id=27093" source="CONFIRM">https://bugzilla.wikimedia.org/show_bug.cgi?id=27093</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65126" source="XF">mediawiki-css-comments-xss(65126)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0273" source="VUPEN" adv="1">ADV-2011-0273</ref>
      <ref url="http://www.securityfocus.com/bid/46108" source="BID">46108</ref>
      <ref url="http://secunia.com/advisories/43142" source="SECUNIA" adv="1">43142</ref>
      <ref url="http://osvdb.org/70770" source="OSVDB">70770</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059235.html" source="FEDORA">FEDORA-2011-5807</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/059232.html" source="FEDORA">FEDORA-2011-5812</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058910.html" source="FEDORA">FEDORA-2011-5848</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.1.0"/>
        <vers num="1.10.0" edition="rc1"/>
        <vers num="1.10.0" edition="rc2"/>
        <vers num="1.10.1"/>
        <vers num="1.10.2"/>
        <vers num="1.10.3"/>
        <vers num="1.10.4"/>
        <vers num="1.11" edition="rc1"/>
        <vers num="1.11.0" edition="rc1"/>
        <vers num="1.11.1"/>
        <vers num="1.11.2"/>
        <vers num="1.12.0" edition="rc1"/>
        <vers num="1.12.1"/>
        <vers num="1.12.2"/>
        <vers num="1.12.3"/>
        <vers num="1.12.4"/>
        <vers num="1.13.0" edition="rc1"/>
        <vers num="1.13.0" edition="rc2"/>
        <vers num="1.13.1"/>
        <vers num="1.13.2"/>
        <vers num="1.13.3"/>
        <vers num="1.13.4"/>
        <vers num="1.14.0" edition="rc1"/>
        <vers num="1.14.1"/>
        <vers num="1.15.0" edition="rc1"/>
        <vers num="1.15.1"/>
        <vers num="1.15.2"/>
        <vers num="1.15.3"/>
        <vers num="1.16.0" edition="beta1"/>
        <vers num="1.16.0" edition="beta2"/>
        <vers prev="1" num="1.16.1"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.10"/>
        <vers num="1.3.11"/>
        <vers num="1.3.12"/>
        <vers num="1.3.13"/>
        <vers num="1.3.14"/>
        <vers num="1.3.15"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.3.5"/>
        <vers num="1.3.6"/>
        <vers num="1.3.7"/>
        <vers num="1.3.8"/>
        <vers num="1.3.9"/>
        <vers num="1.4" edition="beta1"/>
        <vers num="1.4" edition="beta2"/>
        <vers num="1.4" edition="beta3"/>
        <vers num="1.4" edition="beta4"/>
        <vers num="1.4" edition="beta5"/>
        <vers num="1.4" edition="beta6"/>
        <vers num="1.4.0"/>
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers num="1.4.14"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.5" edition="alpha1"/>
        <vers num="1.5" edition="alpha2"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5" edition="beta3"/>
        <vers num="1.5" edition="beta4"/>
        <vers num="1.5" edition="rc2"/>
        <vers num="1.5" edition="rc3"/>
        <vers num="1.5" edition="rc4"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.10"/>
        <vers num="1.6.12"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.5_r14348"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
        <vers num="1.6.9"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
        <vers num="1.7.2"/>
        <vers num="1.7.3"/>
        <vers num="1.8.0"/>
        <vers num="1.8.1"/>
        <vers num="1.8.2"/>
        <vers num="1.8.3"/>
        <vers num="1.8.4"/>
        <vers num="1.8.5"/>
        <vers num="1.9.0" edition="rc2"/>
        <vers num="1.9.1"/>
        <vers num="1.9.2"/>
        <vers num="1.9.3"/>
        <vers num="1.9.4"/>
        <vers num="1.9.5"/>
        <vers num="1.9.6"/>
        <vers num="stable_2003-08-29"/>
        <vers num="stable_2003-11-07"/>
        <vers num="stable_2003-11-17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0048" published="2011-01-28" name="CVE-2011-0048" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XSS) attacks against logged-out users via a crafted URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=628034" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=628034</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65005" source="XF">bugzilla-url-xss(65005)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0271" source="VUPEN">ADV-2011-0271</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0207" source="VUPEN" adv="1">ADV-2011-0207</ref>
      <ref url="http://www.securityfocus.com/bid/45982" source="BID">45982</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2322" source="DEBIAN">DSA-2322</ref>
      <ref url="http://www.bugzilla.org/security/3.2.9/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.2.9/</ref>
      <ref url="http://secunia.com/advisories/43165" source="SECUNIA">43165</ref>
      <ref url="http://secunia.com/advisories/43033" source="SECUNIA" adv="1">43033</ref>
      <ref url="http://osvdb.org/70704" source="OSVDB">70704</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053678.html" source="FEDORA">FEDORA-2011-0755</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-February/053665.html" source="FEDORA">FEDORA-2011-0741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.0"/>
        <vers num="2.10"/>
        <vers num="2.12"/>
        <vers num="2.14"/>
        <vers num="2.14.1"/>
        <vers num="2.14.2"/>
        <vers num="2.14.3"/>
        <vers num="2.14.4"/>
        <vers num="2.14.5"/>
        <vers num="2.16" edition="rc1"/>
        <vers num="2.16" edition="rc2"/>
        <vers num="2.16.1"/>
        <vers num="2.16.10"/>
        <vers num="2.16.11"/>
        <vers num="2.16.2"/>
        <vers num="2.16.3"/>
        <vers num="2.16.4"/>
        <vers num="2.16.5"/>
        <vers num="2.16.6"/>
        <vers num="2.16.7"/>
        <vers num="2.16.8"/>
        <vers num="2.16.9"/>
        <vers num="2.16_rc2"/>
        <vers num="2.17"/>
        <vers num="2.17.1"/>
        <vers num="2.17.2"/>
        <vers num="2.17.3"/>
        <vers num="2.17.4"/>
        <vers num="2.17.5"/>
        <vers num="2.17.6"/>
        <vers num="2.17.7"/>
        <vers num="2.18" edition="rc1"/>
        <vers num="2.18" edition="rc2"/>
        <vers num="2.18" edition="rc3"/>
        <vers num="2.18.1"/>
        <vers num="2.18.2"/>
        <vers num="2.18.3"/>
        <vers num="2.18.4"/>
        <vers num="2.18.5"/>
        <vers num="2.18.6"/>
        <vers num="2.18.6+"/>
        <vers num="2.18.7"/>
        <vers num="2.18.8"/>
        <vers num="2.18.9"/>
        <vers num="2.19"/>
        <vers num="2.19.1"/>
        <vers num="2.19.2"/>
        <vers num="2.19.3"/>
        <vers num="2.2"/>
        <vers num="2.20" edition="rc1"/>
        <vers num="2.20" edition="rc2"/>
        <vers num="2.20.1"/>
        <vers num="2.20.2"/>
        <vers num="2.20.3"/>
        <vers num="2.20.4"/>
        <vers num="2.20.5"/>
        <vers num="2.20.6"/>
        <vers num="2.20.7"/>
        <vers num="2.21"/>
        <vers num="2.21.1"/>
        <vers num="2.21.2"/>
        <vers num="2.22" edition="rc1"/>
        <vers num="2.22.1"/>
        <vers num="2.22.2"/>
        <vers num="2.22.3"/>
        <vers num="2.22.4"/>
        <vers num="2.22.5"/>
        <vers num="2.22.6"/>
        <vers num="2.22.7"/>
        <vers num="2.23"/>
        <vers num="2.23.1"/>
        <vers num="2.23.2"/>
        <vers num="2.23.3"/>
        <vers num="2.23.4"/>
        <vers num="2.4"/>
        <vers num="2.6"/>
        <vers num="2.8"/>
        <vers num="2.9"/>
        <vers num="3.2" edition="rc1"/>
        <vers num="3.2" edition="rc2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.4"/>
        <vers num="3.2.5"/>
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
        <vers prev="1" num="3.2.9"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.4.3"/>
        <vers num="3.4.4"/>
        <vers num="3.4.5"/>
        <vers num="3.4.6"/>
        <vers num="3.4.7"/>
        <vers num="3.4.8"/>
        <vers num="3.4.9"/>
        <vers num="3.6.0"/>
        <vers num="3.6.1"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="4.0" edition="rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0049" published="2011-02-03" name="CVE-2011-0049" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the help command, as demonstrated using (1) a crafted email and (2) cgi-bin/mj_wwwusr in the web interface.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/363726" source="CERT-VN">VU#363726</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=628064" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=628064</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=628064" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=628064</ref>
      <ref url="https://bug628064.bugzilla.mozilla.org/attachment.cgi?id=506481" source="CONFIRM" patch="1">https://bug628064.bugzilla.mozilla.org/attachment.cgi?id=506481</ref>
      <ref url="https://sitewat.ch/en/Advisory/View/1" source="MISC">https://sitewat.ch/en/Advisory/View/1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65113" source="XF">majordomo-listfile-directory-traversal(65113)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0288" source="VUPEN">ADV-2011-0288</ref>
      <ref url="http://www.securitytracker.com/id?1025024" source="SECTRACK">1025024</ref>
      <ref url="http://www.securityfocus.com/bid/46127" source="BID">46127</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516150/100/0/threaded" source="BUGTRAQ">20110203 Majordomo2 - Directory Traversal (SMTP/HTTP)</ref>
      <ref url="http://www.exploit-db.com/exploits/16103" source="EXPLOIT-DB">16103</ref>
      <ref url="http://securityreason.com/securityalert/8061" source="SREASON">8061</ref>
      <ref url="http://secunia.com/advisories/43125" source="SECUNIA" adv="1">43125</ref>
      <ref url="http://osvdb.org/70762" source="OSVDB">70762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mj2" name="majordomo_2">
        <vers num="20110101"/>
        <vers num="20110102"/>
        <vers num="20110103"/>
        <vers num="20110104"/>
        <vers num="20110105"/>
        <vers num="20110106"/>
        <vers num="20110107"/>
        <vers num="20110108"/>
        <vers num="20110109"/>
        <vers num="20110110"/>
        <vers num="20110111"/>
        <vers num="20110112"/>
        <vers num="20110113"/>
        <vers num="20110114"/>
        <vers num="20110115"/>
        <vers num="20110116"/>
        <vers num="20110117"/>
        <vers num="20110118"/>
        <vers num="20110119"/>
        <vers num="20110120"/>
        <vers num="20110121"/>
        <vers num="20110122"/>
        <vers num="20110123"/>
        <vers num="20110124"/>
        <vers num="20110125"/>
        <vers num="20110126"/>
        <vers num="20110127"/>
        <vers num="20110128"/>
        <vers num="20110129"/>
        <vers prev="1" num="20110130"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0050" published="2011-02-18" name="CVE-2011-0050" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the nonjs interface (interfaces/nonjs.pm) in CGI:IRC before 0.5.10 allows remote attackers to inject arbitrary web script or HTML via the R parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0346" source="VUPEN" adv="1">ADV-2011-0346</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516328/100/0/threaded" source="BUGTRAQ">20110209 CGI:IRC XSS issue (CVE-2011-0050)</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2158" source="DEBIAN">DSA-2158</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_id=27024589" source="MLIST">[cgiirc-general] 20110207 CGI:IRC 0.5.10 released to fix XSS issue (CVE-2011-0050)</ref>
      <ref url="http://securityreason.com/securityalert/8097" source="SREASON">8097</ref>
      <ref url="http://secunia.com/advisories/43217" source="SECUNIA" adv="1">43217</ref>
      <ref url="http://osvdb.org/70844" source="OSVDB">70844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgiirc" name="cgi:irc">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.2.1"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.3.2"/>
        <vers num="0.3.3"/>
        <vers num="0.3.3_pre1"/>
        <vers num="0.3.4"/>
        <vers num="0.3.5"/>
        <vers num="0.3.5b"/>
        <vers num="0.3.6"/>
        <vers num="0.3.7"/>
        <vers num="0.3_pre1"/>
        <vers num="0.3_pre2"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="0.5"/>
        <vers num="0.5.1"/>
        <vers num="0.5.2"/>
        <vers num="0.5.3"/>
        <vers num="0.5.4"/>
        <vers num="0.5.5"/>
        <vers num="0.5.6"/>
        <vers num="0.5.7"/>
        <vers num="0.5.8"/>
        <vers prev="1" num="0.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0051" published="2011-03-02" name="CVE-2011-0051" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=616659" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=616659</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0313.html" source="REDHAT">RHSA-2011:0313</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0312.html" source="REDHAT">RHSA-2011:0312</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-02.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100128655" source="CONFIRM">http://support.avaya.com/css/P8/documents/100128655</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14211" source="OVAL">oval:org.mitre.oval:def:14211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0053" published="2011-03-02" name="CVE-2011-0053" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=614499" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=614499</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=613376" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=613376</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=605672" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=605672</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=602115" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=602115</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=600974" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=600974</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=600853" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=600853</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=596232" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=596232</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=576649" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=576649</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=563618" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=563618</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=563243" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=563243</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=558633" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=558633</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=558541" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=558541</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=558531" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=558531</ref>
      <ref url="http://www.securityfocus.com/bid/46645" source="BID">46645</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0313.html" source="REDHAT">RHSA-2011:0313</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0312.html" source="REDHAT">RHSA-2011:0312</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" source="MANDRIVA">MDVSA-2011:042</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100128655" source="CONFIRM">http://support.avaya.com/css/P8/documents/100128655</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14379" source="OVAL">oval:org.mitre.oval:def:14379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers prev="1" num="3.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0054" published="2011-03-02" name="CVE-2011-0054" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving non-local JavaScript variables, aka an "upvarMap" issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=615657" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=615657</ref>
      <ref url="http://www.securityfocus.com/bid/46648" source="BID">46648</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-04.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-04.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14018" source="OVAL">oval:org.mitre.oval:def:14018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0055" published="2011-03-02" name="CVE-2011-0055" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the JSON.stringify method in js3250.dll in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via unspecified vectors related to the js_HasOwnProperty function and garbage collection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=619255" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=619255</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=616009" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=616009</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-103/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-103/</ref>
      <ref url="http://www.securityfocus.com/bid/46661" source="BID">46661</ref>
      <ref url="http://www.securityfocus.com/archive/1/516802" source="BUGTRAQ">20110302 ZDI-11-103: Mozilla Firefox JSON.stringify Dangling Pointer Remote Code Execution Vulnerability</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-03.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-03.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14476" source="OVAL">oval:org.mitre.oval:def:14476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0056" published="2011-03-02" name="CVE-2011-0056" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=622015" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=622015</ref>
      <ref url="http://www.securityfocus.com/bid/46650" source="BID">46650</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-05.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14013" source="OVAL">oval:org.mitre.oval:def:14013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0057" published="2011-03-02" name="CVE-2011-0057" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the Web Workers implementation in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to execute arbitrary code via vectors related to a JavaScript Worker and garbage collection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=626631" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=626631</ref>
      <ref url="http://www.securityfocus.com/bid/46663" source="BID">46663</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-06.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14200" source="OVAL">oval:org.mitre.oval:def:14200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0058" published="2011-03-02" name="CVE-2011-0058" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long string that triggers construction of a long text run.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=607160" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=607160</ref>
      <ref url="http://www.securityfocus.com/bid/46660" source="BID">46660</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-07.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14254" source="OVAL">oval:org.mitre.oval:def:14254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0059" published="2011-03-02" name="CVE-2011-0059" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugin and received a 307 redirect to a page on a different web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=573873" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=573873</ref>
      <ref url="http://www.securityfocus.com/bid/46652" source="BID">46652</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0313.html" source="REDHAT">RHSA-2011:0313</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-10.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-10.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100128655" source="CONFIRM">http://support.avaya.com/css/P8/documents/100128655</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14473" source="OVAL">oval:org.mitre.oval:def:14473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers prev="1" num="3.5.16"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0061" published="2011-03-02" name="CVE-2011-0061" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=610601" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=610601</ref>
      <ref url="http://www.securityfocus.com/bid/46651" source="BID">46651</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-09.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-09.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" source="MANDRIVA">MDVSA-2011:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14486" source="OVAL">oval:org.mitre.oval:def:14486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers prev="1" num="2.0.11"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers prev="1" num="3.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0062" published="2011-03-02" name="CVE-2011-0062" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=599610" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=599610</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=569384" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=569384</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:042" source="MANDRIVA">MDVSA-2011:042</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:041" source="MANDRIVA">MDVSA-2011:041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14409" source="OVAL">oval:org.mitre.oval:def:14409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0063" published="2011-03-15" name="CVE-2011-0063" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct directory traversal attacks and read arbitrary files via a ./.../ sequence in the "extra" parameter to the help command, which causes the regular expression to produce .. (dot dot) sequences.  NOTE: this vulnerability is due to an incomplete fix for CVE-2011-0049.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=631307" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=631307</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66011" source="XF">majordomo-listfileget-dir-traversal(66011)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516923/100/0/threaded" source="BUGTRAQ">20110308 NSOADV-2011-003: Majordomo2 'help' Command Directory Traversal (Patch Bypass)</ref>
      <ref url="http://sotiriu.de/adv/NSOADV-2011-003.txt" source="MISC">http://sotiriu.de/adv/NSOADV-2011-003.txt</ref>
      <ref url="http://securityreason.com/securityalert/8133" source="SREASON">8133</ref>
      <ref url="http://secunia.com/advisories/43631" source="SECUNIA" adv="1">43631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mj2" name="majordomo_2">
        <vers num="20110101"/>
        <vers num="20110102"/>
        <vers num="20110103"/>
        <vers num="20110104"/>
        <vers num="20110105"/>
        <vers num="20110106"/>
        <vers num="20110107"/>
        <vers num="20110108"/>
        <vers num="20110109"/>
        <vers num="20110110"/>
        <vers num="20110111"/>
        <vers num="20110112"/>
        <vers num="20110113"/>
        <vers num="20110114"/>
        <vers num="20110115"/>
        <vers num="20110116"/>
        <vers num="20110117"/>
        <vers num="20110118"/>
        <vers num="20110119"/>
        <vers num="20110120"/>
        <vers num="20110121"/>
        <vers num="20110122"/>
        <vers num="20110123"/>
        <vers num="20110124"/>
        <vers num="20110125"/>
        <vers num="20110126"/>
        <vers num="20110127"/>
        <vers num="20110128"/>
        <vers num="20110129"/>
        <vers num="20110130"/>
        <vers num="20110131"/>
        <vers num="20110201"/>
        <vers num="20110202"/>
        <vers prev="1" num="20110203"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0064" published="2011-03-07" name="CVE-2011-0064" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html 
'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://build.opensuse.org/request/show/63070" source="CONFIRM" patch="1">https://build.opensuse.org/request/show/63070</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=678563" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=678563</ref>
      <ref url="http://cgit.freedesktop.org/harfbuzz/commit/?id=a6a79df5fe2ed2cd307e7a991346faee164e70d9" source="CONFIRM" patch="1">http://cgit.freedesktop.org/harfbuzz/commit/?id=a6a79df5fe2ed2cd307e7a991346faee164e70d9</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=672502" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=672502</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=606997" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=606997</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65770" source="XF">pango-hbbufferensure-bo(65770)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0683" source="VUPEN">ADV-2011-0683</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0584" source="VUPEN">ADV-2011-0584</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0558" source="VUPEN" adv="1">ADV-2011-0558</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0555" source="VUPEN" adv="1">ADV-2011-0555</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0543" source="VUPEN" adv="1">ADV-2011-0543</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1082-1" source="UBUNTU">USN-1082-1</ref>
      <ref url="http://www.securityfocus.com/bid/46632" source="BID">46632</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0309.html" source="REDHAT">RHSA-2011:0309</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:040" source="MANDRIVA">MDVSA-2011:040</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2178" source="DEBIAN">DSA-2178</ref>
      <ref url="http://securitytracker.com/id?1025145" source="SECTRACK">1025145</ref>
      <ref url="http://secunia.com/advisories/43800" source="SECUNIA">43800</ref>
      <ref url="http://secunia.com/advisories/43578" source="SECUNIA" adv="1">43578</ref>
      <ref url="http://secunia.com/advisories/43572" source="SECUNIA" adv="1">43572</ref>
      <ref url="http://secunia.com/advisories/43559" source="SECUNIA" adv="1">43559</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056065.html" source="FEDORA">FEDORA-2011-3194</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num=""/>
      </prod>
      <prod vendor="pango" name="pango">
        <vers num="1.28.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0065" published="2011-05-07" name="CVE-2011-0065" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=634986" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=634986</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://securityreason.com/securityalert/8340" source="SREASON">8340</ref>
      <ref url="http://securityreason.com/securityalert/8331" source="SREASON">8331</ref>
      <ref url="http://securityreason.com/securityalert/8326" source="SREASON">8326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14142" source="OVAL">oval:org.mitre.oval:def:14142</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0066" published="2011-05-07" name="CVE-2011-0066" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=634983" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=634983</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13970" source="OVAL">oval:org.mitre.oval:def:13970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0067" published="2011-05-07" name="CVE-2011-0067" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=527935" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=527935</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-14.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14523" source="OVAL">oval:org.mitre.oval:def:14523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0069" published="2011-05-07" name="CVE-2011-0069" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0070.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=644069" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=644069</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14065" source="OVAL">oval:org.mitre.oval:def:14065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0070" published="2011-05-07" name="CVE-2011-0070" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before 3.1.10; and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0069.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=645565" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=645565</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14286" source="OVAL">oval:org.mitre.oval:def:14286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0071" published="2011-05-07" name="CVE-2011-0071" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=624764" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=624764</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-16.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-16.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14058" source="OVAL">oval:org.mitre.oval:def:14058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0072" published="2011-05-07" name="CVE-2011-0072" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0074, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=624187" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=624187</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14038" source="OVAL">oval:org.mitre.oval:def:14038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0073" published="2011-05-07" name="CVE-2011-0073" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=630919" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=630919</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-13.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-13.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://securityreason.com/securityalert/8310" source="SREASON">8310</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14020" source="OVAL">oval:org.mitre.oval:def:14020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0074" published="2011-05-07" name="CVE-2011-0074" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0075, CVE-2011-0077, and CVE-2011-0078.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=619021" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=619021</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14317" source="OVAL">oval:org.mitre.oval:def:14317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0075" published="2011-05-07" name="CVE-2011-0075" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0077, and CVE-2011-0078.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=635977" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=635977</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14086" source="OVAL">oval:org.mitre.oval:def:14086</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0076" published="2011-05-07" name="CVE-2011-0076" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Embedding Plugin (JEP) in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, on Mac OS X allows remote attackers to bypass intended access restrictions via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=644682" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=644682</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=634724" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=634724</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-15.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-15.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14498" source="OVAL">oval:org.mitre.oval:def:14498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers prev="1" num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0077" published="2011-05-07" name="CVE-2011-0077" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0078.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=623998" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=623998</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14193" source="OVAL">oval:org.mitre.oval:def:14193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0078" published="2011-05-07" name="CVE-2011-0078" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2011-0072, CVE-2011-0074, CVE-2011-0075, and CVE-2011-0077.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=635705" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=635705</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14246" source="OVAL">oval:org.mitre.oval:def:14246</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0079" published="2011-05-07" name="CVE-2011-0079" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to gfx/layers/d3d10/ReadbackManagerD3D10.cpp and unknown other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=639885" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=639885</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=643649" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=643649</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=642717" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=642717</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=641388" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=641388</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=639728" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=639728</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=639343" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=639343</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=601102" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=601102</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14232" source="OVAL">oval:org.mitre.oval:def:14232</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0080" published="2011-05-07" name="CVE-2011-0080" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=638236" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=638236</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=637957" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=637957</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=637621" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=637621</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=634257" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=634257</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=615147" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=615147</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13866" source="OVAL">oval:org.mitre.oval:def:13866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers prev="1" num="2.0.13"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers prev="1" num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0081" published="2011-05-07" name="CVE-2011-0081" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=645289" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=645289</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-12.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-12.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:080" source="MANDRIVA">MDVSA-2011:080</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:079" source="MANDRIVA">MDVSA-2011:079</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2235" source="DEBIAN">DSA-2235</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2228" source="DEBIAN">DSA-2228</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2227" source="DEBIAN">DSA-2227</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13993" source="OVAL">oval:org.mitre.oval:def:13993</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.6.1"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0082" published="2011-06-06" name="CVE-2011-0082" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=709165" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=709165</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=660749" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=660749</ref>
      <ref url="http://www.securityfocus.com/bid/48064" source="BID">48064</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14145" source="OVAL">oval:org.mitre.oval:def:14145</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/05/31/9" source="MLIST">[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/05/31/4" source="MLIST">[oss-security] 20110531 CVE request: firefox doesn't (re)validate certificates when loading HTTPS page</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/05/31/18" source="MLIST">[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page</ref>
      <ref url="http://openwall.com/lists/oss-security/2011/05/31/14" source="MLIST">[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0083" published="2011-06-30" name="CVE-2011-0083" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=648090" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=648090</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1149-1" source="UBUNTU">USN-1149-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0888.html" source="REDHAT">RHSA-2011:0888</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0887.html" source="REDHAT">RHSA-2011:0887</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0886.html" source="REDHAT">RHSA-2011:0886</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0885.html" source="REDHAT">RHSA-2011:0885</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-23.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-23.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:111" source="MANDRIVA">MDVSA-2011:111</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2273" source="DEBIAN">DSA-2273</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2269" source="DEBIAN">DSA-2269</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2268" source="DEBIAN">DSA-2268</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100145333" source="CONFIRM">http://support.avaya.com/css/P8/documents/100145333</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100144854" source="CONFIRM">http://support.avaya.com/css/P8/documents/100144854</ref>
      <ref url="http://secunia.com/advisories/45002" source="SECUNIA">45002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:13543" source="OVAL">oval:org.mitre.oval:def:13543</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html" source="SUSE">SUSE-SA:2011:028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers prev="1" num="3.6.17"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers prev="1" num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0084" published="2011-08-18" name="CVE-2011-0084" modified="2012-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=648094" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=648094</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1166.html" source="REDHAT" adv="1">RHSA-2011:1166</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1164.html" source="REDHAT" adv="1">RHSA-2011:1164</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-33.html" source="CONFIRM">http://www.mozilla.org/security/announce/2011/mfsa2011-33.html</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-31.html" source="CONFIRM">http://www.mozilla.org/security/announce/2011/mfsa2011-31.html</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-30.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-30.html</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-29.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-29.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:127" source="MANDRIVA">MDVSA-2011:127</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2297" source="DEBIAN">DSA-2297</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2296" source="DEBIAN">DSA-2296</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2295" source="DEBIAN">DSA-2295</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14502" source="OVAL">oval:org.mitre.oval:def:14502</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.html" source="SUSE">SUSE-SU-2011:0967</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html" source="SUSE">SUSE-SA:2011:037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers num="3.6.17"/>
        <vers num="3.6.18"/>
        <vers prev="1" num="3.6.19"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta10"/>
        <vers num="4.0" edition="beta11"/>
        <vers num="4.0" edition="beta12"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta5"/>
        <vers num="4.0" edition="beta6"/>
        <vers num="4.0" edition="beta7"/>
        <vers num="4.0" edition="beta8"/>
        <vers num="4.0" edition="beta9"/>
        <vers num="4.0.1"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1" edition="alpha1"/>
        <vers num="2.1" edition="alpha2"/>
        <vers num="2.1" edition="alpha3"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.10"/>
        <vers num="3.1.11"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0085" published="2011-06-30" name="CVE-2011-0085" modified="2012-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=648100" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=648100</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1149-1" source="UBUNTU">USN-1149-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0888.html" source="REDHAT">RHSA-2011:0888</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0887.html" source="REDHAT">RHSA-2011:0887</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0886.html" source="REDHAT">RHSA-2011:0886</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0885.html" source="REDHAT">RHSA-2011:0885</ref>
      <ref url="http://www.mozilla.org/security/announce/2011/mfsa2011-23.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2011/mfsa2011-23.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:111" source="MANDRIVA">MDVSA-2011:111</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2273" source="DEBIAN">DSA-2273</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2269" source="DEBIAN">DSA-2269</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2268" source="DEBIAN">DSA-2268</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100145333" source="CONFIRM">http://support.avaya.com/css/P8/documents/100145333</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100144854" source="CONFIRM">http://support.avaya.com/css/P8/documents/100144854</ref>
      <ref url="http://secunia.com/advisories/45002" source="SECUNIA">45002</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14432" source="OVAL">oval:org.mitre.oval:def:14432</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html" source="SUSE">SUSE-SA:2011:028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" edition="preview_release"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta1"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="2.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.10"/>
        <vers num="2.0.0.11"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.13"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.15"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.20"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.12"/>
        <vers num="3.0.13"/>
        <vers num="3.0.14"/>
        <vers num="3.0.15"/>
        <vers num="3.0.16"/>
        <vers num="3.0.17"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.5"/>
        <vers num="3.5.1"/>
        <vers num="3.5.10"/>
        <vers num="3.5.11"/>
        <vers num="3.5.12"/>
        <vers num="3.5.13"/>
        <vers num="3.5.14"/>
        <vers num="3.5.15"/>
        <vers num="3.5.16"/>
        <vers num="3.5.17"/>
        <vers num="3.5.18"/>
        <vers num="3.5.19"/>
        <vers num="3.5.2"/>
        <vers num="3.5.3"/>
        <vers num="3.5.4"/>
        <vers num="3.5.5"/>
        <vers num="3.5.6"/>
        <vers num="3.5.7"/>
        <vers num="3.5.8"/>
        <vers num="3.5.9"/>
        <vers num="3.6"/>
        <vers num="3.6.10"/>
        <vers num="3.6.11"/>
        <vers num="3.6.12"/>
        <vers num="3.6.13"/>
        <vers num="3.6.14"/>
        <vers num="3.6.15"/>
        <vers num="3.6.16"/>
        <vers prev="1" num="3.6.17"/>
        <vers num="3.6.2"/>
        <vers num="3.6.3"/>
        <vers num="3.6.4"/>
        <vers num="3.6.6"/>
        <vers num="3.6.7"/>
        <vers num="3.6.8"/>
        <vers num="3.6.9"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha"/>
        <vers num="1.0" edition="beta"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1" edition="alpha"/>
        <vers num="1.1" edition="beta"/>
        <vers num="1.1.1"/>
        <vers num="1.1.10"/>
        <vers num="1.1.11"/>
        <vers num="1.1.12"/>
        <vers num="1.1.13"/>
        <vers num="1.1.14"/>
        <vers num="1.1.15"/>
        <vers num="1.1.16"/>
        <vers num="1.1.17"/>
        <vers num="1.1.18"/>
        <vers num="1.1.19"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="1.1.6"/>
        <vers num="1.1.7"/>
        <vers num="1.1.8"/>
        <vers num="1.1.9"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="2.0" edition="alpha_1"/>
        <vers num="2.0" edition="alpha_2"/>
        <vers num="2.0" edition="alpha_3"/>
        <vers num="2.0" edition="beta_1"/>
        <vers num="2.0" edition="beta_2"/>
        <vers num="2.0" edition="rc1"/>
        <vers num="2.0" edition="rc2"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.7.2"/>
        <vers num="0.7.3"/>
        <vers num="0.8"/>
        <vers num="0.9"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.5" edition="beta2"/>
        <vers num="1.5.0.1"/>
        <vers num="1.5.0.10"/>
        <vers num="1.5.0.11"/>
        <vers num="1.5.0.12"/>
        <vers num="1.5.0.13"/>
        <vers num="1.5.0.14"/>
        <vers num="1.5.0.2"/>
        <vers num="1.5.0.3"/>
        <vers num="1.5.0.4"/>
        <vers num="1.5.0.5"/>
        <vers num="1.5.0.6"/>
        <vers num="1.5.0.7"/>
        <vers num="1.5.0.8"/>
        <vers num="1.5.0.9"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.7.1"/>
        <vers num="1.7.3"/>
        <vers num="2.0"/>
        <vers num="2.0.0.0"/>
        <vers num="2.0.0.1"/>
        <vers num="2.0.0.12"/>
        <vers num="2.0.0.14"/>
        <vers num="2.0.0.16"/>
        <vers num="2.0.0.17"/>
        <vers num="2.0.0.18"/>
        <vers num="2.0.0.19"/>
        <vers num="2.0.0.2"/>
        <vers num="2.0.0.21"/>
        <vers num="2.0.0.22"/>
        <vers num="2.0.0.23"/>
        <vers num="2.0.0.3"/>
        <vers num="2.0.0.4"/>
        <vers num="2.0.0.5"/>
        <vers num="2.0.0.6"/>
        <vers num="2.0.0.7"/>
        <vers num="2.0.0.8"/>
        <vers num="2.0.0.9"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.10"/>
        <vers num="3.0.11"/>
        <vers num="3.0.2"/>
        <vers num="3.0.3"/>
        <vers num="3.0.4"/>
        <vers num="3.0.5"/>
        <vers num="3.0.6"/>
        <vers num="3.0.7"/>
        <vers num="3.0.8"/>
        <vers num="3.0.9"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers prev="1" num="3.1.10"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.1.5"/>
        <vers num="3.1.6"/>
        <vers num="3.1.7"/>
        <vers num="3.1.8"/>
        <vers num="3.1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0086" published="2011-02-08" name="CVE-2011-0086" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-012.mspx" source="MS" patch="1" adv="1">MS11-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0325" source="VUPEN" adv="1">ADV-2011-0325</ref>
      <ref url="http://www.securityfocus.com/bid/46141" source="BID">46141</ref>
      <ref url="http://secunia.com/advisories/43255" source="SECUNIA">43255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12070" source="OVAL">oval:org.mitre.oval:def:12070</ref>
      <ref url="http://osvdb.org/70818" source="OSVDB">70818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0087" published="2011-02-08" name="CVE-2011-0087" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-012.mspx" source="MS" patch="1" adv="1">MS11-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0325" source="VUPEN" adv="1">ADV-2011-0325</ref>
      <ref url="http://www.securityfocus.com/bid/46148" source="BID">46148</ref>
      <ref url="http://secunia.com/advisories/43255" source="SECUNIA" adv="1">43255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12312" source="OVAL">oval:org.mitre.oval:def:12312</ref>
      <ref url="http://osvdb.org/70819" source="OSVDB">70819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0088" published="2011-02-08" name="CVE-2011-0088" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-012.mspx" source="MS" patch="1" adv="1">MS11-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0325" source="VUPEN" adv="1">ADV-2011-0325</ref>
      <ref url="http://www.securityfocus.com/bid/46147" source="BID">46147</ref>
      <ref url="http://secunia.com/advisories/43255" source="SECUNIA" adv="1">43255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12553" source="OVAL">oval:org.mitre.oval:def:12553</ref>
      <ref url="http://osvdb.org/70816" source="OSVDB">70816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0089" published="2011-02-08" name="CVE-2011-0089" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-012.mspx" source="MS" patch="1" adv="1">MS11-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0325" source="VUPEN" adv="1">ADV-2011-0325</ref>
      <ref url="http://www.securityfocus.com/bid/46149" source="BID">46149</ref>
      <ref url="http://secunia.com/advisories/43255" source="SECUNIA" adv="1">43255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11638" source="OVAL">oval:org.mitre.oval:def:11638</ref>
      <ref url="http://osvdb.org/70817" source="OSVDB">70817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0090" published="2011-02-08" name="CVE-2011-0090" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-012.mspx" source="MS" patch="1" adv="1">MS11-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0325" source="VUPEN" adv="1">ADV-2011-0325</ref>
      <ref url="http://www.securityfocus.com/bid/46150" source="BID">46150</ref>
      <ref url="http://secunia.com/advisories/43255" source="SECUNIA" adv="1">43255</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12455" source="OVAL">oval:org.mitre.oval:def:12455</ref>
      <ref url="http://osvdb.org/70814" source="OSVDB">70814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="r2"/>
        <vers num="" edition="r2:x64"/>
        <vers num="" edition="r2:itanium"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="-" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:x64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0091" published="2011-02-10" name="CVE-2011-0091" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-013.mspx" source="MS" patch="1" adv="1">MS11-013</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64901" source="XF">ms-kerberos-spoofing(64901)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0326" source="VUPEN">ADV-2011-0326</ref>
      <ref url="http://www.securitytracker.com/id?1025048" source="SECTRACK">1025048</ref>
      <ref url="http://www.securityfocus.com/bid/46140" source="BID">46140</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100127250" source="CONFIRM">http://support.avaya.com/css/P8/documents/100127250</ref>
      <ref url="http://secunia.com/advisories/43257" source="SECUNIA">43257</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12498" source="OVAL">oval:org.mitre.oval:def:12498</ref>
      <ref url="http://osvdb.org/70835" source="OSVDB">70835</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0092" published="2011-02-10" name="CVE-2011-0092" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-008.mspx" source="MS" patch="1" adv="1">MS11-008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64923" source="XF">ms-visio-object-code-execution(64923)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-063/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-063/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0321" source="VUPEN" adv="1">ADV-2011-0321</ref>
      <ref url="http://www.securitytracker.com/id?1025043" source="SECTRACK">1025043</ref>
      <ref url="http://www.securityfocus.com/bid/46137" source="BID">46137</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516274/100/0/threaded" source="BUGTRAQ">20110208 ZDI-11-063: Microsoft Visio 2007 LZW Stream Decompression Exception Vulnerability</ref>
      <ref url="http://secunia.com/advisories/43254" source="SECUNIA" adv="1">43254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12403" source="OVAL">oval:org.mitre.oval:def:12403</ref>
      <ref url="http://osvdb.org/70828" source="OSVDB">70828</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0093" published="2011-02-10" name="CVE-2011-0093" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-008.mspx" source="MS" patch="1" adv="1">MS11-008</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64924" source="XF">ms-visio-data-code-execution(64924)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0321" source="VUPEN">ADV-2011-0321</ref>
      <ref url="http://www.securitytracker.com/id?1025043" source="SECTRACK">1025043</ref>
      <ref url="http://www.securityfocus.com/bid/46138" source="BID">46138</ref>
      <ref url="http://secunia.com/advisories/43254" source="SECUNIA">43254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12469" source="OVAL">oval:org.mitre.oval:def:12469</ref>
      <ref url="http://osvdb.org/70829" source="OSVDB">70829</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0094" published="2011-04-13" name="CVE-2011-0094" modified="2011-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layouts Handling Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-018.mspx" source="MS" patch="1" adv="1">MS11-018</ref>
      <ref url="http://www.securitytracker.com/id?1025327" source="SECTRACK">1025327</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12463" source="OVAL">oval:org.mitre.oval:def:12463</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=900" source="IDEFENSE">20110412 Microsoft Internet Explorer Use-After-Free Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0096" published="2011-01-31" name="CVE-2011-0096" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/326549" source="CERT-VN">VU#326549</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65000" source="XF">ms-win-mhtml-info-disclosure(65000)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0242" source="VUPEN" adv="1">ADV-2011-0242</ref>
      <ref url="http://www.securitytracker.com/id?1025003" source="SECTRACK">1025003</ref>
      <ref url="http://www.securityfocus.com/bid/46055" source="BID">46055</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-026.mspx" source="MS">MS11-026</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/2501696.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/2501696.mspx</ref>
      <ref url="http://www.exploit-db.com/exploits/16071" source="EXPLOIT-DB">16071</ref>
      <ref url="http://www.80vul.com/webzine_0x05/0x05%20IE%E4%B8%8BMHTML%E5%8D%8F%E8%AE%AE%E5%B8%A6%E6%9D%A5%E7%9A%84%E8%B7%A8%E5%9F%9F%E5%8D%B1%E5%AE%B3.html" source="MISC">http://www.80vul.com/webzine_0x05/0x05%20IE%E4%B8%8BMHTML%E5%8D%8F%E8%AE%AE%E5%B8%A6%E6%9D%A5%E7%9A%84%E8%B7%A8%E5%9F%9F%E5%8D%B1%E5%AE%B3.html</ref>
      <ref url="http://secunia.com/advisories/43093" source="SECUNIA" adv="1">43093</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6956" source="OVAL">oval:org.mitre.oval:def:6956</ref>
      <ref url="http://osvdb.org/70693" source="OSVDB">70693</ref>
      <ref url="http://blogs.technet.com/b/srd/archive/2011/01/28/more-information-about-the-mhtml-script-injection-vulnerability.aspx" source="CONFIRM">http://blogs.technet.com/b/srd/archive/2011/01/28/more-information-about-the-mhtml-script-injection-vulnerability.aspx</ref>
      <ref url="http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx" source="CONFIRM">http://blogs.technet.com/b/msrc/archive/2011/01/28/microsoft-releases-security-advisory-2501696.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x32"/>
        <vers num="-" edition="-:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium"/>
        <vers num="" edition=":x64"/>
        <vers num="" edition=":x32"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp2:x32"/>
        <vers num="-" edition="sp2"/>
        <vers num="-" edition="sp2:itanium"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":x64"/>
        <vers num="r2" edition=":itanium"/>
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:x64"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:x64"/>
        <vers num="" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0097" published="2011-04-13" name="CVE-2011-0097" modified="2013-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which triggers a stack-based buffer overflow, aka "Excel Integer Overrun Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN" adv="1">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://www.securityfocus.com/bid/47201" source="BID">47201</ref>
      <ref url="http://secunia.com/secunia_research/2011-31" source="MISC" adv="1">http://secunia.com/secunia_research/2011-31</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA" adv="1">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12612" source="OVAL">oval:org.mitre.oval:def:12612</ref>
      <ref url="http://osvdb.org/71758" source="OSVDB">71758</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2010"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0098" published="2011-04-13" name="CVE-2011-0098" modified="2013-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via an XLS file with a large record size, aka "Excel Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN" adv="1">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://www.securityfocus.com/bid/47235" source="BID">47235</ref>
      <ref url="http://secunia.com/secunia_research/2011-32/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-32/</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA" adv="1">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12034" source="OVAL">oval:org.mitre.oval:def:12034</ref>
      <ref url="http://osvdb.org/71759" source="OSVDB">71759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="-" edition="-"/>
        <vers num="-" edition="-:x64"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="2010"/>
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="-" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0101" published="2011-04-13" name="CVE-2011-0101" modified="2013-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-120" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-120</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN" adv="1">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://www.securityfocus.com/bid/47243" source="BID">47243</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517463/100/0/threaded" source="BUGTRAQ">20110412 ZDI-11-120: Microsoft Office Excel RealTimeData Record Parsing Remote Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA" adv="1">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11676" source="OVAL">oval:org.mitre.oval:def:11676</ref>
      <ref url="http://osvdb.org/71766" source="OSVDB">71766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0103" published="2011-04-13" name="CVE-2011-0103" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://www.securityfocus.com/bid/47244" source="BID">47244</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12616" source="OVAL">oval:org.mitre.oval:def:12616</ref>
      <ref url="http://osvdb.org/71760" source="OSVDB">71760</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=901" source="IDEFENSE">20110412 Microsoft Excel Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0104" published="2011-04-13" name="CVE-2011-0104" modified="2013-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN" adv="1">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://www.securityfocus.com/bid/47245" source="BID">47245</ref>
      <ref url="http://www.checkpoint.com/defense/advisories/public/2011/cpai-31-Mard.html" source="MISC">http://www.checkpoint.com/defense/advisories/public/2011/cpai-31-Mard.html</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA" adv="1">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11767" source="OVAL">oval:org.mitre.oval:def:11767</ref>
      <ref url="http://osvdb.org/71761" source="OSVDB">71761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0105" published="2011-04-13" name="CVE-2011-0105" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-021.mspx" source="MS" patch="1" adv="1">MS11-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0940" source="VUPEN">ADV-2011-0940</ref>
      <ref url="http://www.securitytracker.com/id?1025337" source="SECTRACK">1025337</ref>
      <ref url="http://secunia.com/advisories/39122" source="SECUNIA">39122</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12618" source="OVAL">oval:org.mitre.oval:def:12618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2002" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="2008" edition=""/>
        <vers num="2008" edition=":mac"/>
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0107" published="2011-04-13" name="CVE-2011-0107" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/426.html 
'CWE-426: Untrusted Search Path'</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS11-023.mspx

Access Vector: Network per "This is a remote code execution vulnerability"</impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-023.mspx" source="MS" patch="1" adv="1">MS11-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0942" source="VUPEN">ADV-2011-0942</ref>
      <ref url="http://www.securitytracker.com/id?1025343" source="SECTRACK">1025343</ref>
      <ref url="http://www.securityfocus.com/bid/47246" source="BID">47246</ref>
      <ref url="http://www.fortiguard.com/advisory/FGA-2011-13.html" source="MISC">http://www.fortiguard.com/advisory/FGA-2011-13.html</ref>
      <ref url="http://secunia.com/advisories/44015" source="SECUNIA">44015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12655" source="OVAL">oval:org.mitre.oval:def:12655</ref>
      <ref url="http://osvdb.org/71767" source="OSVDB">71767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="sp3"/>
        <vers num="2007" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0111" published="2011-03-03" name="CVE-2011-0111" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0112" published="2011-03-03" name="CVE-2011-0112" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0113" published="2011-03-03" name="CVE-2011-0113" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0114" published="2011-03-03" name="CVE-2011-0114" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0115" published="2011-03-03" name="CVE-2011-0115" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The DOM level 2 implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, does not properly handle DOM manipulations associated with event listeners during processing of range objects, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-096" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-096</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0116" published="2011-03-03" name="CVE-2011-0116" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the setOuterText method in the htmlelement library in WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to DOM manipulations during iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-097" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-097</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0117" published="2011-03-03" name="CVE-2011-0117" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0118" published="2011-03-03" name="CVE-2011-0118" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0119" published="2011-03-03" name="CVE-2011-0119" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0120" published="2011-03-03" name="CVE-2011-0120" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0121" published="2011-03-03" name="CVE-2011-0121" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0122" published="2011-03-03" name="CVE-2011-0122" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0123" published="2011-03-03" name="CVE-2011-0123" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0124" published="2011-03-03" nvd_name="Test" name="CVE-2011-0124" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0125" published="2011-03-03" name="CVE-2011-0125" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0126" published="2011-03-03" name="CVE-2011-0126" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0127" published="2011-03-03" name="CVE-2011-0127" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0128" published="2011-03-03" name="CVE-2011-0128" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0129" published="2011-03-03" name="CVE-2011-0129" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0130" published="2011-03-03" name="CVE-2011-0130" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0131" published="2011-03-03" name="CVE-2011-0131" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0132" published="2011-03-03" name="CVE-2011-0132" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the Runin box functionality in the Cascading Style Sheets (CSS) 2.1 Visual Formatting Model implementation in WebKit, as used in Apple iTunes before 10.2 on Windows and Apple Safari, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-098" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-098</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="safari">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0133" published="2011-03-03" name="CVE-2011-0133" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly access glyph data during layout actions for floating blocks associated with pseudo-elements, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-099" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-099</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0134" published="2011-03-03" name="CVE-2011-0134" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0135" published="2011-03-03" name="CVE-2011-0135" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0136" published="2011-03-03" name="CVE-2011-0136" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0137" published="2011-03-03" name="CVE-2011-0137" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0138" published="2011-03-03" name="CVE-2011-0138" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0139" published="2011-03-03" name="CVE-2011-0139" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0140" published="2011-03-03" name="CVE-2011-0140" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0141" published="2011-03-03" name="CVE-2011-0141" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0142" published="2011-03-03" name="CVE-2011-0142" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0143" published="2011-03-03" name="CVE-2011-0143" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0144" published="2011-03-03" name="CVE-2011-0144" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0145" published="2011-03-03" name="CVE-2011-0145" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0146" published="2011-03-03" name="CVE-2011-0146" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0147" published="2011-03-03" name="CVE-2011-0147" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0148" published="2011-03-03" name="CVE-2011-0148" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0149" published="2011-03-03" name="CVE-2011-0149" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, does not properly parse HTML elements associated with document namespaces, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to a "dangling pointer" and iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-100" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-100</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0150" published="2011-03-03" name="CVE-2011-0150" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0151" published="2011-03-03" name="CVE-2011-0151" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0152" published="2011-03-03" name="CVE-2011-0152" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12519" source="OVAL">oval:org.mitre.oval:def:12519</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0153" published="2011-03-03" name="CVE-2011-0153" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0154" published="2011-03-03" name="CVE-2011-0154" modified="2012-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-101" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-101</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0155" published="2011-03-03" name="CVE-2011-0155" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0156" published="2011-03-03" name="CVE-2011-0156" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0157" published="2011-03-11" name="CVE-2011-0157" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">WebKit, as used in Apple iOS before 4.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-09-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66007" source="XF">appleios-webkit-unspec-code-exec(66007)</ref>
      <ref url="http://www.securityfocus.com/bid/46807" source="BID">46807</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0158" published="2011-03-11" name="CVE-2011-0158" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">MobileSafari in Apple iOS before 4.3 does not properly implement application launching through URL handlers, which allows remote attackers to cause a denial of service (persistent application crash) via crafted JavaScript code.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66002" source="XF">appleios-mobilesafari-dos(66002)</ref>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://www.securityfocus.com/bid/46806" source="BID">46806</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0159" published="2011-03-11" name="CVE-2011-0159" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Safari Settings feature in Safari in Apple iOS 4.x before 4.3 does not properly implement the clearing of cookies during execution of the Safari application, which might make it easier for remote web servers to track users by setting a cookie.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://www.securityfocus.com/bid/46810" source="BID">46810</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="4.0"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0160" published="2011-03-11" name="CVE-2011-0160" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle redirects in conjunction with HTTP Basic Authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0161" published="2011-03-11" name="CVE-2011-0161" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle the Attr.style accessor, which allows remote attackers to bypass the Same Origin Policy and inject Cascading Style Sheets (CSS) token sequences via a crafted web site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66000" source="XF">appleios-attr-code-execution(66000)</ref>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://www.securityfocus.com/bid/46814" source="BID">46814</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0162" published="2011-03-11" name="CVE-2011-0162" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Wi-Fi in Apple iOS before 4.3 and Apple TV before 4.2 does not properly perform bounds checking for Wi-Fi frames, which allows remote attackers to cause a denial of service (device reset) via unspecified traffic on the local wireless network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65998" source="XF">appleios-wifi-dos(65998)</ref>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://www.securityfocus.com/bid/46813" source="BID">46813</ref>
      <ref url="http://support.apple.com/kb/HT4565" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4565</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00005.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="apple_tv">
        <vers num="1.0.0"/>
        <vers num="1.1.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="4.0"/>
        <vers prev="1" num="4.1"/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0163" published="2011-03-11" name="CVE-2011-0163" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poisoning attack.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66001" source="XF">appleios-cache-dos(66001)</ref>
      <ref url="http://www.securitytracker.com/id?1025182" source="SECTRACK">1025182</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers prev="1" num="4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0164" published="2011-03-03" name="CVE-2011-0164" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0165" published="2011-03-03" name="CVE-2011-0165" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0166" published="2011-03-11" name="CVE-2011-0166" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via vectors related to the dragging of content.  NOTE: this might overlap CVE-2011-0778.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66004" source="XF">apple-safari-html5-info-disclosure(66004)</ref>
      <ref url="http://www.securitytracker.com/id?1025183" source="SECTRACK">1025183</ref>
      <ref url="http://www.securityfocus.com/bid/46811" source="BID">46811</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0167" published="2011-03-11" name="CVE-2011-0167" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025183" source="SECTRACK">1025183</ref>
      <ref url="http://www.securityfocus.com/bid/46816" source="BID">46816</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0168" published="2011-03-03" name="CVE-2011-0168" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0169" published="2011-03-11" name="CVE-2011-0169" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66006" source="XF">safari-commandlineapi-xss(66006)</ref>
      <ref url="http://www.securitytracker.com/id?1025183" source="SECTRACK">1025183</ref>
      <ref url="http://www.securityfocus.com/bid/46809" source="BID">46809</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-03-09-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers prev="1" num="5.0.3"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0170" published="2011-03-03" name="CVE-2011-0170" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a JPEG image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=897" source="IDEFENSE">20110302 Apple CoreGraphics Library Heap Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0172" published="2011-03-22" name="CVE-2011-0172" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0173" published="2011-03-22" name="CVE-2011-0173" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="applescript">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0174" published="2011-03-22" name="CVE-2011-0174" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0175" published="2011-03-22" name="CVE-2011-0175" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0176" published="2011-03-22" name="CVE-2011-0176" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0177" published="2011-03-22" name="CVE-2011-0177" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0178" published="2011-03-22" name="CVE-2011-0178" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="carboncore">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0179" published="2011-03-22" name="CVE-2011-0179" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0180" published="2011-03-22" name="CVE-2011-0180" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0181" published="2011-03-22" name="CVE-2011-0181" modified="2011-06-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0182" published="2011-03-22" name="CVE-2011-0182" modified="2012-02-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://securityreason.com/securityalert/8402" source="SREASON">8402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0183" published="2011-03-22" name="CVE-2011-0183" modified="2011-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers prev="1" num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0184" published="2011-03-22" name="CVE-2011-0184" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=898" source="IDEFENSE">20110321 Apple OfficeImport Framework Excel Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0185" published="2011-10-14" name="CVE-2011-0185" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50092" source="BID">50092</ref>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM" adv="1">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0186" published="2011-03-22" name="CVE-2011-0186" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0187" published="2011-03-22" name="CVE-2011-0187" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0188" published="2011-03-22" name="CVE-2011-0188" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The VpMemAlloc function in bigdecimal.c in the BigDecimal class in Ruby 1.9.2-p136 and earlier, as used on Apple Mac OS X before 10.6.7 and other platforms, does not properly allocate memory, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving creation of a large BigDecimal value within a 64-bit process, related to an "integer truncation issue."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html

 'This issue only affects 64-bit Ruby processes'. </impact>
    </impacts>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=682332" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=682332</ref>
      <ref url="http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&amp;r2=30993" source="CONFIRM" patch="1" adv="1">http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ext/bigdecimal/bigdecimal.c?r1=29364&amp;r2=30993</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://www.securitytracker.com/id?1025236" source="SECTRACK">1025236</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0910.html" source="REDHAT">RHSA-2011:0910</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0909.html" source="REDHAT">RHSA-2011:0909</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0908.html" source="REDHAT">RHSA-2011:0908</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:098" source="MANDRIVA">MDVSA-2011:098</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:097" source="MANDRIVA">MDVSA-2011:097</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ruby-lang" name="ruby">
        <vers num="1.9" edition="r18423"/>
        <vers num="1.9.0" edition="r18423"/>
        <vers num="1.9.0-0"/>
        <vers num="1.9.0-1"/>
        <vers num="1.9.0-2"/>
        <vers num="1.9.0-20060415"/>
        <vers num="1.9.0-20070709"/>
        <vers num="1.9.1" edition="-p0"/>
        <vers num="1.9.1" edition="-p129"/>
        <vers num="1.9.1" edition="-p243"/>
        <vers num="1.9.1" edition="-p376"/>
        <vers num="1.9.1" edition="-p429"/>
        <vers num="1.9.1" edition="-preview_1"/>
        <vers num="1.9.1" edition="-preview_2"/>
        <vers num="1.9.1" edition="-rc1"/>
        <vers num="1.9.1" edition="-rc2"/>
        <vers num="1.9.2" edition="dev"/>
        <vers prev="1" num="1.9.2-p136"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0189" published="2011-03-22" name="CVE-2011-0189" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="terminal">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0190" published="2011-03-22" name="CVE-2011-0190" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="installer">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0191" published="2011-03-03" name="CVE-2011-0191" modified="2011-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0859" source="VUPEN">ADV-2011-0859</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0845" source="VUPEN">ADV-2011-0845</ref>
      <ref url="http://www.securityfocus.com/bid/46657" source="BID">46657</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:064" source="MANDRIVA">MDVSA-2011:064</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2210" source="DEBIAN">DSA-2210</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4565" source="CONFIRM">http://support.apple.com/kb/HT4565</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://secunia.com/advisories/43934" source="SECUNIA">43934</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00005.html" source="APPLE">APPLE-SA-2011-03-09-3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0192" published="2011-03-03" name="CVE-2011-0192" modified="2013-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-02-1</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=678635" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=678635</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0960" source="VUPEN">ADV-2011-0960</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0930" source="VUPEN">ADV-2011-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0905" source="VUPEN">ADV-2011-0905</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0845" source="VUPEN">ADV-2011-0845</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0621" source="VUPEN">ADV-2011-0621</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0599" source="VUPEN">ADV-2011-0599</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0551" source="VUPEN">ADV-2011-0551</ref>
      <ref url="http://www.securitytracker.com/id?1025153" source="SECTRACK">1025153</ref>
      <ref url="http://www.securityfocus.com/bid/46658" source="BID">46658</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0318.html" source="REDHAT">RHSA-2011:0318</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:043" source="MANDRIVA">MDVSA-2011:043</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2210" source="DEBIAN">DSA-2210</ref>
      <ref url="http://support.apple.com/kb/HT5001" source="CONFIRM">http://support.apple.com/kb/HT5001</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://support.apple.com/kb/HT4566" source="CONFIRM">http://support.apple.com/kb/HT4566</ref>
      <ref url="http://support.apple.com/kb/HT4565" source="CONFIRM">http://support.apple.com/kb/HT4565</ref>
      <ref url="http://support.apple.com/kb/HT4564" source="CONFIRM">http://support.apple.com/kb/HT4564</ref>
      <ref url="http://support.apple.com/kb/HT4554" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4554</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2011&amp;m=slackware-security.587820" source="SLACKWARE">SSA:2011-098-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201209-02.xml" source="GENTOO">GLSA-201209-02</ref>
      <ref url="http://secunia.com/advisories/50726" source="SECUNIA">50726</ref>
      <ref url="http://secunia.com/advisories/44135" source="SECUNIA">44135</ref>
      <ref url="http://secunia.com/advisories/44117" source="SECUNIA">44117</ref>
      <ref url="http://secunia.com/advisories/43934" source="SECUNIA">43934</ref>
      <ref url="http://secunia.com/advisories/43664" source="SECUNIA">43664</ref>
      <ref url="http://secunia.com/advisories/43593" source="SECUNIA">43593</ref>
      <ref url="http://secunia.com/advisories/43585" source="SECUNIA">43585</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055683.html" source="FEDORA">FEDORA-2011-2498</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055240.html" source="FEDORA">FEDORA-2011-2540</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057840.html" source="FEDORA">FEDORA-2011-3827</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/057763.html" source="FEDORA">FEDORA-2011-3836</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE">APPLE-SA-2011-03-21-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html" source="APPLE">APPLE-SA-2011-10-12-2</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00005.html" source="APPLE">APPLE-SA-2011-03-09-3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html" source="APPLE">APPLE-SA-2011-03-09-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html" source="APPLE">APPLE-SA-2011-03-09-1</ref>
      <ref url="http://blackberry.com/btsc/KB27244" source="CONFIRM">http://blackberry.com/btsc/KB27244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers prev="1" num="10.1.2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0193" published="2011-03-22" name="CVE-2011-0193" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0194" published="2011-03-22" name="CVE-2011-0194" modified="2011-03-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4581" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4581</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-03-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0195" published="2011-04-15" name="CVE-2011-0195" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site.  NOTE: this may overlap CVE-2011-1202.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025365" source="SECTRACK">1025365</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Apr/msg00000.html" source="APPLE" adv="1">APPLE-SA-2011-04-14-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0196" published="2011-06-24" name="CVE-2011-0196" modified="2011-06-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">AirPort in Apple Mac OS X 10.5.8 allows remote attackers to cause a denial of service (out-of-bounds read and reboot) via Wi-Fi frames on the local wireless network.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0197" published="2011-06-24" name="CVE-2011-0197" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48443" source="BID">48443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0198" published="2011-06-24" name="CVE-2011-0198" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48436" source="BID">48436</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0199" published="2011-06-24" name="CVE-2011-0199" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48447" source="BID">48447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0200" published="2011-06-24" name="CVE-2011-0200" modified="2012-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://support.apple.com/kb/HT5130" source="CONFIRM">http://support.apple.com/kb/HT5130</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html" source="APPLE">APPLE-SA-2012-02-01-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0201" published="2011-06-24" name="CVE-2011-0201" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0202" published="2011-06-24" name="CVE-2011-0202" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0203" published="2011-06-24" name="CVE-2011-0203" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48418" source="BID">48418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0204" published="2011-06-24" name="CVE-2011-0204" modified="2011-11-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://osvdb.org/73368" source="OSVDB">73368</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2011-07/0034.html" source="BUGTRAQ">20110628 NGS00062 Patch Notification: Apple Mac OS X ImageIO TIFF Heap Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0205" published="2011-06-24" name="CVE-2011-0205" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48439" source="BID">48439</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0206" published="2011-06-24" name="CVE-2011-0206" modified="2011-11-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/68217" source="XF">macos-icu-bo(68217)</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE">APPLE-SA-2011-07-20-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0207" published="2011-06-24" name="CVE-2011-0207" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48444" source="BID">48444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0208" published="2011-06-24" name="CVE-2011-0208" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0209" published="2011-06-24" name="CVE-2011-0209" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0210" published="2011-06-24" name="CVE-2011-0210" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48442" source="BID">48442</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0211" published="2011-06-24" name="CVE-2011-0211" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0212" published="2011-06-24" name="CVE-2011-0212" modified="2011-10-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://www.securityfocus.com/bid/48445" source="BID">48445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0213" published="2011-06-24" name="CVE-2011-0213" modified="2011-08-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4723" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT4723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-06-23-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0214" published="2011-07-21" name="CVE-2011-0214" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote web servers to bypass intended SSL restrictions via a certificate signed by a blacklisted certification authority.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cfnetwork">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0215" published="2011-07-21" name="CVE-2011-0215" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0216" published="2011-07-21" name="CVE-2011-0216" modified="2013-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Off-by-one error in libxml in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1749.html" source="REDHAT">RHSA-2011:1749</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:188" source="MANDRIVA">MDVSA-2011:188</ref>
      <ref url="http://www.debian.org/security/2012/dsa-2394" source="DEBIAN">DSA-2394</ref>
      <ref url="http://support.apple.com/kb/HT5001" source="CONFIRM">http://support.apple.com/kb/HT5001</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2013-0217.html" source="REDHAT">RHSA-2013:0217</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html" source="APPLE">APPLE-SA-2011-10-12-2</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0217" published="2011-07-21" name="CVE-2011-0217" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0218" published="2011-07-21" name="CVE-2011-0218" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0219" published="2011-07-21" name="CVE-2011-0219" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a Java applet that loads fonts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0221" published="2011-07-21" name="CVE-2011-0221" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0222" published="2011-07-21" name="CVE-2011-0222" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://securityreason.com/securityalert/8315" source="SREASON">8315</ref>
      <ref url="http://securityreason.com/securityalert/8313" source="SREASON">8313</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0223" published="2011-07-21" name="CVE-2011-0223" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0224" published="2011-10-14" name="CVE-2011-0224" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50095" source="BID">50095</ref>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM" adv="1">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers prev="1" num="10.6.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers prev="1" num="10.6.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0225" published="2011-07-21" name="CVE-2011-0225" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0226" published="2011-07-19" name="CVE-2011-0226" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/48619" source="BID">48619</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1085.html" source="REDHAT">RHSA-2011:1085</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:120" source="MANDRIVA">MDVSA-2011:120</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2294" source="DEBIAN">DSA-2294</ref>
      <ref url="http://www.appleinsider.com/articles/11/07/06/hackers_release_new_browser_based_ios_jailbreak_based_on_pdf_exploit.html" source="MISC">http://www.appleinsider.com/articles/11/07/06/hackers_release_new_browser_based_ios_jailbreak_based_on_pdf_exploit.html</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://support.apple.com/kb/HT4803" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4803</ref>
      <ref url="http://support.apple.com/kb/HT4802" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4802</ref>
      <ref url="http://secunia.com/advisories/45224" source="SECUNIA" adv="1">45224</ref>
      <ref url="http://secunia.com/advisories/45167" source="SECUNIA" adv="1">45167</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00016.html" source="SUSE">SUSE-SU-2011:0853</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00015.html" source="SUSE">openSUSE-SU-2011:0852</ref>
      <ref url="http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00028.html" source="MLIST">[freetype-devel] 20110711 Re: details on iPhone exploit caused by FreeType?</ref>
      <ref url="http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00026.html" source="MLIST">[freetype-devel] 20110711 Re: details on iPhone exploit caused by FreeType?</ref>
      <ref url="http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00020.html" source="MLIST">[freetype-devel] 20110709 Re: details on iPhone exploit caused by FreeType?</ref>
      <ref url="http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00015.html" source="MLIST">[freetype-devel] 20110708 Re: details on iPhone exploit caused by FreeType?</ref>
      <ref url="http://lists.nongnu.org/archive/html/freetype-devel/2011-07/msg00014.html" source="MLIST">[freetype-devel] 20110708 details on iPhone exploit caused by FreeType?</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00001.html" source="APPLE" adv="1">APPLE-SA-2011-07-15-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00000.html" source="APPLE" adv="1">APPLE-SA-2011-07-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freetype" name="freetype">
        <vers num="2.2.1"/>
        <vers num="2.2.10"/>
        <vers num="2.3.0"/>
        <vers num="2.3.1"/>
        <vers num="2.3.10"/>
        <vers num="2.3.11"/>
        <vers num="2.3.12"/>
        <vers num="2.3.2"/>
        <vers num="2.3.3"/>
        <vers num="2.3.4"/>
        <vers num="2.3.5"/>
        <vers num="2.3.6"/>
        <vers num="2.3.7"/>
        <vers num="2.3.8"/>
        <vers num="2.3.9"/>
        <vers num="2.4.0"/>
        <vers num="2.4.1"/>
        <vers num="2.4.2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers prev="1" num="2.4.5"/>
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.2"/>
        <vers num="4.2.1"/>
        <vers num="4.2.5"/>
        <vers prev="1" num="4.2.8"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0227" published="2011-07-19" name="CVE-2011-0227" modified="2011-07-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows local users to gain privileges via a crafted application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4803" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4803</ref>
      <ref url="http://support.apple.com/kb/HT4802" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4802</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00001.html" source="APPLE" adv="1">APPLE-SA-2011-07-15-2</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00000.html" source="APPLE" adv="1">APPLE-SA-2011-07-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.2.1"/>
        <vers num="4.2.5"/>
        <vers prev="1" num="4.2.8"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0228" published="2011-08-29" name="CVE-2011-0228" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2011-007.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2011-007.txt</ref>
      <ref url="http://www.securityfocus.com/bid/48877" source="BID">48877</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/518982/100/0/threaded" source="BUGTRAQ">20110725 TWSL2011-007: iOS SSL Implementation Does Not Validate Certificate Chain</ref>
      <ref url="http://support.apple.com/kb/HT4825" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4825</ref>
      <ref url="http://support.apple.com/kb/HT4824" source="CONFIRM">http://support.apple.com/kb/HT4824</ref>
      <ref url="http://securitytracker.com/id?1025837" source="SECTRACK">1025837</ref>
      <ref url="http://securityreason.com/securityalert/8361" source="SREASON">8361</ref>
      <ref url="http://secunia.com/advisories/45369" source="SECUNIA" adv="1">45369</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00005.html" source="APPLE" adv="1">APPLE-SA-2011-07-25-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00004.html" source="APPLE" adv="1">APPLE-SA-2011-07-25-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
        <vers num="1.1.5"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.1"/>
        <vers num="3.1.2"/>
        <vers num="3.1.3"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.1"/>
        <vers num="4.2.1"/>
        <vers num="4.2.5"/>
        <vers num="4.2.8"/>
        <vers prev="1" num="4.2.9"/>
        <vers num="4.3.0"/>
        <vers num="4.3.1"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0229" published="2011-10-14" name="CVE-2011-0229" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Apple Type Services (ATS) in Apple Mac OS X through 10.6.8 does not properly handle embedded Type 1 fonts, which allows remote attackers to execute arbitrary code via a crafted document that triggers an out-of-bounds memory access.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50091" source="BID">50091</ref>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers prev="1" num="10.6.8"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers prev="1" num="10.6.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0230" published="2011-10-14" name="CVE-2011-0230" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in the ATSFontDeactivate API in Apple Type Services (ATS) in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM" adv="1">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0231" published="2011-10-14" name="CVE-2011-0231" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X before 10.7.2 does not properly follow an intended cookie-storage policy, which makes it easier for remote web servers to track users via a cookie, related to a "synchronization issue."</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0"/>
        <vers num="10.0.0"/>
        <vers num="10.0.1"/>
        <vers num="10.0.2"/>
        <vers num="10.0.3"/>
        <vers num="10.0.4"/>
        <vers num="10.1"/>
        <vers num="10.1.0"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.1.3"/>
        <vers num="10.1.4"/>
        <vers num="10.1.5"/>
        <vers num="10.2"/>
        <vers num="10.2.0"/>
        <vers num="10.2.1"/>
        <vers num="10.2.2"/>
        <vers num="10.2.3"/>
        <vers num="10.2.4"/>
        <vers num="10.2.5"/>
        <vers num="10.2.6"/>
        <vers num="10.2.7"/>
        <vers num="10.2.8"/>
        <vers num="10.3"/>
        <vers num="10.3.0"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.0"/>
        <vers num="10.4.1"/>
        <vers num="10.4.10"/>
        <vers num="10.4.11"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
        <vers num="10.4.6"/>
        <vers num="10.4.7"/>
        <vers num="10.4.8"/>
        <vers num="10.4.9"/>
        <vers num="10.5"/>
        <vers num="10.5.0"/>
        <vers num="10.5.1"/>
        <vers num="10.5.2"/>
        <vers num="10.5.3"/>
        <vers num="10.5.4"/>
        <vers num="10.5.5"/>
        <vers num="10.5.6"/>
        <vers num="10.5.7"/>
        <vers num="10.5.8"/>
        <vers num="10.6.0"/>
        <vers num="10.6.1"/>
        <vers num="10.6.2"/>
        <vers num="10.6.3"/>
        <vers num="10.6.4"/>
        <vers num="10.6.5"/>
        <vers num="10.6.6"/>
        <vers num="10.6.7"/>
        <vers num="10.6.8"/>
        <vers num="10.7.0"/>
        <vers prev="1" num="10.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0232" published="2011-07-21" name="CVE-2011-0232" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0233" published="2011-07-21" name="CVE-2011-0233" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0234" published="2011-07-21" name="CVE-2011-0234" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0235" published="2011-07-21" name="CVE-2011-0235" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0237" published="2011-07-21" name="CVE-2011-0237" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0238" published="2011-07-21" name="CVE-2011-0238" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0240" published="2011-07-21" name="CVE-2011-0240" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0241" published="2011-07-21" name="CVE-2011-0241" modified="2012-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ImageIO in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with CCITT Group 4 encoding.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT5281" source="CONFIRM">http://support.apple.com/kb/HT5281</ref>
      <ref url="http://support.apple.com/kb/HT5130" source="CONFIRM">http://support.apple.com/kb/HT5130</ref>
      <ref url="http://support.apple.com/kb/HT5001" source="CONFIRM">http://support.apple.com/kb/HT5001</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/May/msg00001.html" source="APPLE">APPLE-SA-2012-05-09-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html" source="APPLE">APPLE-SA-2012-02-01-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html" source="APPLE">APPLE-SA-2011-10-12-2</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="imageio">
        <vers num=""/>
      </prod>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0242" published="2011-07-21" name="CVE-2011-0242" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving a URL that contains a username.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0244" published="2011-07-21" name="CVE-2011-0244" modified="2011-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM">http://support.apple.com/kb/HT4808</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0245" published="2011-08-03" name="CVE-2011-0245" modified="2012-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pict file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
        <vers num="7.66.71.0"/>
        <vers num="7.67.75.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0246" published="2011-08-03" name="CVE-2011-0246" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0247" published="2011-08-03" name="CVE-2011-0247" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Apple QuickTime before 7.7 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0248" published="2011-08-03" name="CVE-2011-0248" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0249" published="2011-08-03" name="CVE-2011-0249" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSC atoms in a QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0250" published="2011-08-03" name="CVE-2011-0250" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSS atoms in a QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0251" published="2011-08-03" name="CVE-2011-0251" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSZ atoms in a QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0252" published="2011-08-03" name="CVE-2011-0252" modified="2012-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STTS atoms in a QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Aug/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-08-03-1</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
        <vers num="7.66.71.0"/>
        <vers num="7.67.75.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0253" published="2011-07-21" name="CVE-2011-0253" modified="2011-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0254" published="2011-07-21" name="CVE-2011-0254" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0255" published="2011-07-21" name="CVE-2011-0255" modified="2011-10-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-07-20-1</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://support.apple.com/kb/HT4808" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4808</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE">APPLE-SA-2011-10-11-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="1.0" edition="beta"/>
        <vers num="1.0" edition="beta2"/>
        <vers num="1.0.0"/>
        <vers num="1.0.0b1"/>
        <vers num="1.0.0b2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3" edition="85.8"/>
        <vers num="1.0.3" edition="85.8.1"/>
        <vers num="1.1"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.2"/>
        <vers num="1.2.0"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.3"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2" edition="312.5"/>
        <vers num="1.3.2" edition="312.6"/>
        <vers num="2"/>
        <vers num="2.0"/>
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3" edition="417.8"/>
        <vers num="2.0.3" edition="417.9"/>
        <vers num="2.0.3" edition="417.9.2"/>
        <vers num="2.0.3" edition="417.9.3"/>
        <vers num="2.0.4"/>
        <vers num="3"/>
        <vers num="3.0"/>
        <vers num="3.0.0"/>
        <vers num="3.0.0b"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1b"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2b"/>
        <vers num="3.0.3"/>
        <vers num="3.0.3b"/>
        <vers num="3.0.4"/>
        <vers num="3.0.4b"/>
        <vers num="3.1.0"/>
        <vers num="3.1.0b"/>
        <vers num="3.1.1"/>
        <vers num="3.1.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="4.1"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers prev="1" num="5.0.5"/>
      </prod>
      <prod vendor="apple" name="webkit">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0256" published="2011-08-15" name="CVE-2011-0256" modified="2012-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted track run atoms in a QuickTime movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT4826" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4826</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
        <vers num="7.66.71.0"/>
        <vers num="7.67.75.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0257" published="2011-08-15" name="CVE-2011-0257" modified="2012-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-11-252/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-11-252/</ref>
      <ref url="http://www.exploit-db.com/exploits/17777" source="EXPLOIT-DB">17777</ref>
      <ref url="http://support.apple.com/kb/HT4826" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4826</ref>
      <ref url="http://securityreason.com/securityalert/8365" source="SREASON">8365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
        <vers num="7.66.71.0"/>
        <vers num="7.67.75.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0258" published="2011-09-06" name="CVE-2011-0258" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image description associated with an mp4v tag in a movie file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-11-277/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-11-277/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/69518" source="XF">quicktime-mp4v-bo(69518)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/519483/100/0/threaded" source="BUGTRAQ">20110831 ZDI-11-277: Apple QuickTime 3g2 'mp4v' atom size Remote Code Execution Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT4826" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4826</ref>
      <ref url="http://securityreason.com/securityalert/8368" source="SREASON">8368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3.0"/>
        <vers num="4.1.2"/>
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="6.0"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.2.0"/>
        <vers num="6.3.0"/>
        <vers num="6.4.0"/>
        <vers num="6.5"/>
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="7.0"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.0.3"/>
        <vers num="7.0.4"/>
        <vers num="7.1"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.1.3"/>
        <vers num="7.1.4"/>
        <vers num="7.1.5"/>
        <vers num="7.1.6"/>
        <vers num="7.2"/>
        <vers num="7.2.0"/>
        <vers num="7.2.1"/>
        <vers num="7.3"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.1.70"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.5"/>
        <vers num="7.5.0"/>
        <vers num="7.5.5"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.6.5"/>
        <vers num="7.6.6"/>
        <vers num="7.6.7"/>
        <vers num="7.6.8"/>
        <vers prev="1" num="7.6.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0259" published="2011-10-12" name="CVE-2011-0259" modified="2011-12-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">CoreFoundation, as used in Apple iTunes before 10.5, does not properly perform string tokenization, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2011-10-11-1</ref>
      <ref url="http://www.securityfocus.com/bid/50067" source="BID">50067</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://support.apple.com/kb/HT4999" source="CONFIRM">http://support.apple.com/kb/HT4999</ref>
      <ref url="http://support.apple.com/kb/HT4981" source="CONFIRM" adv="1">http://support.apple.com/kb/HT4981</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE">APPLE-SA-2011-10-12-3</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html" source="APPLE">APPLE-SA-2011-10-12-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="10.0"/>
        <vers num="10.0.1"/>
        <vers num="10.1"/>
        <vers num="10.1.1"/>
        <vers num="10.1.2"/>
        <vers num="10.2"/>
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.4"/>
        <vers prev="1" num="10.4.1"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.1.0"/>
        <vers num="4.2.0"/>
        <vers num="4.5"/>
        <vers num="4.5.0"/>
        <vers num="4.6"/>
        <vers num="4.6.0"/>
        <vers num="4.7"/>
        <vers num="4.7.0"/>
        <vers num="4.7.1"/>
        <vers num="4.7.2"/>
        <vers num="4.8.0"/>
        <vers num="4.9.0"/>
        <vers num="5.0"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.4.2"/>
        <vers num="6.0.5"/>
        <vers num="7.0.0"/>
        <vers num="7.0.1"/>
        <vers num="7.0.2"/>
        <vers num="7.1.0"/>
        <vers num="7.1.1"/>
        <vers num="7.2.0"/>
        <vers num="7.3.0"/>
        <vers num="7.3.1"/>
        <vers num="7.3.2"/>
        <vers num="7.4"/>
        <vers num="7.4.0"/>
        <vers num="7.4.1"/>
        <vers num="7.4.2"/>
        <vers num="7.4.3"/>
        <vers num="7.5"/>
        <vers num="7.5.0"/>
        <vers num="7.6"/>
        <vers num="7.6.0"/>
        <vers num="7.6.1"/>
        <vers num="7.6.2"/>
        <vers num="7.7"/>
        <vers num="7.7.0"/>
        <vers num="7.7.1"/>
        <vers num="8.0.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.1"/>
        <vers num="8.1.1"/>
        <vers num="8.2"/>
        <vers num="8.2.1"/>
        <vers num="9.0.0"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.3"/>
        <vers num="9.2"/>
        <vers num="9.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0260" published="2011-10-14" name="CVE-2011-0260" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/50085" source="BID">50085</ref>
      <ref url="http://support.apple.com/kb/HT5002" source="CONFIRM" adv="1">http://support.apple.com/kb/HT5002</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html" source="APPLE" adv="1">APPLE-SA-2011-10-12-3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.7.0"/>
        <vers num="10.7.1"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.7.0"/>
        <vers num="10.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0261" published="2011-01-13" name="CVE-2011-0261" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a malformed displayWidth option in the arg parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64655" source="XF">hp-opennnm-jovgraph-bo(64655)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-003/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-003/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0262" published="2011-01-13" name="CVE-2011-0262" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via large values of variables to jovgraph.exe.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64654" source="XF">hp-opennnm-ovutildll-bo(64654)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-004/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-004/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0263" published="2011-01-13" name="CVE-2011-0263" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) Source Node or (2) Destination Node variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64653" source="XF">hp-opennnm-ovas-bo(64653)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-005/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-005/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0264" published="2011-01-13" name="CVE-2011-0264" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long COOKIE variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64652" source="XF">hp-opennnm-ovutil-bo(64652)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-006/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-006/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0265" published="2011-01-13" name="CVE-2011-0265" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long data_select1 parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64651" source="XF">hp-opennnm-dataselect1-bo(64651)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-007/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-007/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0266" published="2011-01-13" name="CVE-2011-0266" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64650" source="XF">hp-opennnm-nameparams-bo(64650)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-008/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-008/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://securityreason.com/securityalert/8151" source="SREASON">8151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0267" published="2011-01-13" name="CVE-2011-0267" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attackers to execute arbitrary code via a long (1) schdParams or (2) nameParams parameter, a different vulnerability than CVE-2011-0266.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64649" source="XF">hp-opennnm-schdparams-bo(64649)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-009/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-009/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.exploit-db.com/exploits/17038" source="EXPLOIT-DB">17038</ref>
      <ref url="http://securityreason.com/securityalert/8156" source="SREASON">8156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0268" published="2011-01-13" name="CVE-2011-0268" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long text1 parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64648" source="XF">hp-opennnm-text1-bo(64648)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-010/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-010/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0269" published="2011-01-13" name="CVE-2011-0269" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long schd_select1 parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64647" source="XF">hp-opennnm-schdselect1-bo(64647)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-011/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-011/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">SSRT100352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0270" published="2011-01-13" name="CVE-2011-0270" modified="2011-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in input data that involves an invalid template name.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64646" source="XF">hp-opennnm-nnmrptconfig-format-string(64646)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-012/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-012/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://osvdb.org/70474" source="OSVDB">70474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0271" published="2011-01-13" name="CVE-2011-0271" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64657" source="XF">hp-opennnm-cgi-command-exec(64657)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0085" source="VUPEN">ADV-2011-0085</ref>
      <ref url="http://www.securitytracker.com/id?1024951" source="SECTRACK">1024951</ref>
      <ref url="http://www.securityfocus.com/bid/45762" source="BID">45762</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://www.securityfocus.com/archive/1/515628" source="HP">HPSBMA02621</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=887" source="IDEFENSE">20110110 HP Network Node Manager Command Injection Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51"/>
        <vers num="7.53"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0272" published="2011-01-18" name="CVE-2011-0272" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64659" source="XF">loadrunner-unspec-code-execution(64659)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0095" source="VUPEN" adv="1">ADV-2011-0095</ref>
      <ref url="http://www.securityfocus.com/bid/45792" source="BID">45792</ref>
      <ref url="http://www.securityfocus.com/archive/1/515682" source="HP">HPSBMA02624</ref>
      <ref url="http://www.securityfocus.com/archive/1/515682" source="HP">HPSBMA02624</ref>
      <ref url="http://securitytracker.com/id?1024956" source="SECTRACK">1024956</ref>
      <ref url="http://secunia.com/advisories/42898" source="SECUNIA" adv="1">42898</ref>
      <ref url="http://osvdb.org/70432" source="OSVDB">70432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="loadrunner">
        <vers num="9.52"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0273" published="2011-01-24" name="CVE-2011-0273" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in crs.exe in HP OpenView Storage Data Protector Cell Manager 6.11 allows remote attackers to execute arbitrary code via unspecified message types.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64818" source="XF">hp-openview-storage-code-execution(64818)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-024/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-024/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0177" source="VUPEN" adv="1">ADV-2011-0177</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02688353" source="HP">SSRT100138</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02688353" source="HP">SSRT100138</ref>
      <ref url="http://securitytracker.com/id?1024983" source="SECTRACK">1024983</ref>
      <ref url="http://secunia.com/advisories/42997" source="SECUNIA" adv="1">42997</ref>
      <ref url="http://osvdb.org/70621" source="OSVDB">70621</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_storage_data_protector_cell_manager">
        <vers num="6.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0274" published="2011-01-24" name="CVE-2011-0274" modified="2011-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64846" source="XF">hp-bac-bsm-xss(64846)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0188" source="VUPEN" adv="1">ADV-2011-0188</ref>
      <ref url="http://www.securityfocus.com/bid/45944" source="BID">45944</ref>
      <ref url="http://securitytracker.com/id?1024986" source="SECTRACK">1024986</ref>
      <ref url="http://secunia.com/advisories/43018" source="SECUNIA" adv="1">43018</ref>
      <ref url="http://secunia.com/advisories/43014" source="SECUNIA" adv="1">43014</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562482815203&amp;w=2" source="HP" adv="1">SSRT100342</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129562482815203&amp;w=2" source="HP" adv="1">SSRT100342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="business_availability_center">
        <vers num="7.0"/>
        <vers num="7.55"/>
        <vers num="8.0"/>
        <vers num="8.05"/>
      </prod>
      <prod vendor="hp" name="business_service_management">
        <vers num="9.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0275" published="2011-01-28" name="CVE-2011-0275" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64932" source="XF">hp-openview-storage-dos(64932)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0218" source="VUPEN" adv="1">ADV-2011-0218</ref>
      <ref url="http://www.securityfocus.com/bid/46018" source="BID">46018</ref>
      <ref url="http://securitytracker.com/id?1024991" source="SECTRACK">1024991</ref>
      <ref url="http://secunia.com/advisories/43088" source="SECUNIA" adv="1">43088</ref>
      <ref url="http://osvdb.org/70657" source="OSVDB">70657</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02699143" source="HP" adv="1">HPSBMA02626</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02699143" source="HP" adv="1">HPSBMA02626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_storage_data_protector">
        <vers num="6.0"/>
        <vers num="6.10"/>
        <vers num="6.11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0276" published="2011-02-01" name="CVE-2011-0276" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65038" source="XF">openview-dopost-code-execution(65038)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-034" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-034</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0258" source="VUPEN" adv="1">ADV-2011-0258</ref>
      <ref url="http://www.securitytracker.com/id?1025014" source="SECTRACK">1025014</ref>
      <ref url="http://www.securityfocus.com/bid/46079" source="BID">46079</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516093/100/0/threaded" source="BUGTRAQ">20110131 ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability</ref>
      <ref url="http://www.exploit-db.com/exploits/16984" source="EXPLOIT-DB">16984</ref>
      <ref url="http://securityreason.com/securityalert/8136" source="SREASON">8136</ref>
      <ref url="http://secunia.com/advisories/43145" source="SECUNIA" adv="1">43145</ref>
      <ref url="http://osvdb.org/70754" source="OSVDB">70754</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02695453" source="HP" adv="1">HPSBMA02627</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02695453" source="HP" adv="1">HPSBMA02627</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_performance_insight">
        <vers num="5.2"/>
        <vers num="5.3"/>
        <vers num="5.31"/>
        <vers num="5.4"/>
        <vers num="5.41"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0277" published="2011-02-08" name="CVE-2011-0277" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025032" source="SECTRACK">1025032</ref>
      <ref url="http://www.securityfocus.com/bid/46258" source="BID">46258</ref>
      <ref url="http://secunia.com/advisories/43058" source="SECUNIA" adv="1">43058</ref>
      <ref url="http://osvdb.org/70836" source="OSVDB">70836</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02711131" source="HP">HPSBMA02629</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02711131" source="HP">HPSBMA02629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="power_manager">
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers prev="1" num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0278" published="2011-03-01" name="CVE-2011-0278" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0516" source="VUPEN" adv="1">ADV-2011-0516</ref>
      <ref url="http://www.securityfocus.com/bid/46595" source="BID">46595</ref>
      <ref url="http://securitytracker.com/id?1025130" source="SECTRACK">1025130</ref>
      <ref url="http://secunia.com/advisories/43526" source="SECUNIA" adv="1">43526</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02714670" source="HP" adv="1">HPSBPI02635</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02714670" source="HP" adv="1">HPSBPI02635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="web_jetadmin">
        <vers num="10.2" edition="sr3"/>
        <vers num="10.2" edition="sr4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0279" published="2011-03-07" name="CVE-2011-0279" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65866" source="XF">hp-mfpdigitalsending-sec-bypass(65866)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0561" source="VUPEN">ADV-2011-0561</ref>
      <ref url="http://www.securitytracker.com/id?1025155" source="SECTRACK">1025155</ref>
      <ref url="http://www.securityfocus.com/bid/46679" source="BID">46679</ref>
      <ref url="http://secunia.com/advisories/43618" source="SECUNIA" adv="1">43618</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02738104" source="HP">SSRT100410</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02738104" source="HP">HPSBPI02640</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="multifunction_peripheral_digital_sending_software">
        <vers num="4.91.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0280" published="2011-03-14" name="CVE-2011-0280" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66035" source="XF">powermanager-unspecified-xss(66035)</ref>
      <ref url="http://www.securityfocus.com/bid/46830" source="BID">46830</ref>
      <ref url="http://secunia.com/advisories/43058" source="SECUNIA" adv="1">43058</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2011-03/0111.html" source="HP">SSRT100381</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2011-03/0111.html" source="HP">HPSBMA02629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="power_manager">
        <vers num="4.2.5"/>
        <vers num="4.2.6"/>
        <vers num="4.2.7"/>
        <vers num="4.2.8"/>
        <vers num="4.2.9"/>
        <vers prev="1" num="4.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0281" published="2011-02-10" name="CVE-2011-0281" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (file descriptor exhaustion and daemon hang) via a principal name that triggers use of a backslash escape sequence, as demonstrated by a \n sequence.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65324" source="XF">kerberos-ldap-descriptor-dos(65324)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0464" source="VUPEN">ADV-2011-0464</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0347" source="VUPEN" adv="1">ADV-2011-0347</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0333" source="VUPEN" adv="1">ADV-2011-0333</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0330" source="VUPEN" adv="1">ADV-2011-0330</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0012.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0012.html</ref>
      <ref url="http://www.securitytracker.com/id?1025037" source="SECTRACK">1025037</ref>
      <ref url="http://www.securityfocus.com/bid/46265" source="BID">46265</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded" source="BUGTRAQ">20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516299/100/0/threaded" source="BUGTRAQ">20110208 MITKRB5-SA-2011-002 KDC denial of service attacks [CVE-2011-0281 CVE-2011-0282 CVE-2011-0283]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0200.html" source="REDHAT">RHSA-2011:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0199.html" source="REDHAT">RHSA-2011:0199</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:025" source="MANDRIVA">MDVSA-2011:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:024" source="MANDRIVA">MDVSA-2011:024</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/8073" source="SREASON">8073</ref>
      <ref url="http://secunia.com/advisories/46397" source="SECUNIA">46397</ref>
      <ref url="http://secunia.com/advisories/43275" source="SECUNIA" adv="1">43275</ref>
      <ref url="http://secunia.com/advisories/43273" source="SECUNIA" adv="1">43273</ref>
      <ref url="http://secunia.com/advisories/43260" source="SECUNIA" adv="1">43260</ref>
      <ref url="http://mailman.mit.edu/pipermail/kerberos/2010-December/016800.html" source="MLIST">[kerberos] 20101222 LDAP handle unavailable: Can't contact LDAP server</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html" source="SUSE">SUSE-SR:2011:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.6"/>
        <vers num="5-1.6.1"/>
        <vers num="5-1.6.2"/>
        <vers num="5-1.6.3"/>
        <vers num="5-1.7"/>
        <vers num="5-1.7.1"/>
        <vers num="5-1.8"/>
        <vers num="5-1.8.1"/>
        <vers num="5-1.8.2"/>
        <vers num="5-1.8.3"/>
        <vers num="5-1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0282" published="2011-02-10" name="CVE-2011-0282" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65323" source="XF">kerberos-ldap-dos(65323)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0464" source="VUPEN">ADV-2011-0464</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0347" source="VUPEN" adv="1">ADV-2011-0347</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0333" source="VUPEN" adv="1">ADV-2011-0333</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0330" source="VUPEN" adv="1">ADV-2011-0330</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0012.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0012.html</ref>
      <ref url="http://www.securitytracker.com/id?1025037" source="SECTRACK">1025037</ref>
      <ref url="http://www.securityfocus.com/bid/46271" source="BID">46271</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/520102/100/0/threaded" source="BUGTRAQ">20111013 VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516299/100/0/threaded" source="BUGTRAQ">20110208 MITKRB5-SA-2011-002 KDC denial of service attacks [CVE-2011-0281 CVE-2011-0282 CVE-2011-0283]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0200.html" source="REDHAT">RHSA-2011:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0199.html" source="REDHAT">RHSA-2011:0199</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:025" source="MANDRIVA">MDVSA-2011:025</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:024" source="MANDRIVA">MDVSA-2011:024</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/8073" source="SREASON">8073</ref>
      <ref url="http://secunia.com/advisories/46397" source="SECUNIA">46397</ref>
      <ref url="http://secunia.com/advisories/43275" source="SECUNIA" adv="1">43275</ref>
      <ref url="http://secunia.com/advisories/43273" source="SECUNIA" adv="1">43273</ref>
      <ref url="http://secunia.com/advisories/43260" source="SECUNIA" adv="1">43260</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00004.html" source="SUSE">SUSE-SR:2011:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.6"/>
        <vers num="5-1.6.1"/>
        <vers num="5-1.6.2"/>
        <vers num="5-1.6.3"/>
        <vers num="5-1.7"/>
        <vers num="5-1.7.1"/>
        <vers num="5-1.8"/>
        <vers num="5-1.8.1"/>
        <vers num="5-1.8.2"/>
        <vers num="5-1.8.3"/>
        <vers num="5-1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0283" published="2011-02-10" name="CVE-2011-0283" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request packet that does not trigger a response packet.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0330" source="VUPEN" adv="1">ADV-2011-0330</ref>
      <ref url="http://www.securitytracker.com/id?1025037" source="SECTRACK">1025037</ref>
      <ref url="http://www.securityfocus.com/bid/46272" source="BID">46272</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516299/100/0/threaded" source="BUGTRAQ">20110208 MITKRB5-SA-2011-002 KDC denial of service attacks [CVE-2011-0281 CVE-2011-0282 CVE-2011-0283]</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/8073" source="SREASON">8073</ref>
      <ref url="http://secunia.com/advisories/43260" source="SECUNIA" adv="1">43260</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0284" published="2011-03-19" name="CVE-2011-0284" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/943220" source="CERT-VN" patch="1">VU#943220</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-003.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-003.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66101" source="XF">kerberos-perpareerroras-code-execution(66101)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0763" source="VUPEN">ADV-2011-0763</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0722" source="VUPEN">ADV-2011-0722</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0680" source="VUPEN">ADV-2011-0680</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0673" source="VUPEN" adv="1">ADV-2011-0673</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0672" source="VUPEN" adv="1">ADV-2011-0672</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1088-1" source="UBUNTU">USN-1088-1</ref>
      <ref url="http://www.securityfocus.com/bid/46881" source="BID">46881</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517029/100/0/threaded" source="BUGTRAQ">20110315 MITKRB5-SA-2011-003 [CVE-2011-0284] KDC double-free when PKINIT enabled</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0356.html" source="REDHAT">RHSA-2011:0356</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:048" source="MANDRIVA">MDVSA-2011:048</ref>
      <ref url="http://securitytracker.com/id?1025216" source="SECTRACK">1025216</ref>
      <ref url="http://secunia.com/advisories/43881" source="SECUNIA">43881</ref>
      <ref url="http://secunia.com/advisories/43783" source="SECUNIA" adv="1">43783</ref>
      <ref url="http://secunia.com/advisories/43760" source="SECUNIA">43760</ref>
      <ref url="http://secunia.com/advisories/43700" source="SECUNIA">43700</ref>
      <ref url="http://osvdb.org/71183" source="OSVDB">71183</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056579.html" source="FEDORA">FEDORA-2011-3462</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056573.html" source="FEDORA">FEDORA-2011-3464</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056413.html" source="FEDORA">FEDORA-2011-3547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7"/>
        <vers num="5-1.7.1"/>
        <vers num="5-1.8"/>
        <vers num="5-1.8.1"/>
        <vers num="5-1.8.2"/>
        <vers num="5-1.8.3"/>
        <vers num="5-1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0285" published="2011-04-14" name="CVE-2011-0285" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517484/100/0/threaded" source="BUGTRAQ" patch="1">20110413 MITKRB5-SA-2011-004 kadmind invalid pointer free() [CVE-2011-0285]</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-004.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2011-004.txt</ref>
      <ref url="https://hermes.opensuse.org/messages/8086843" source="SUSE">openSUSE-SU-2011:0348</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0997" source="VUPEN">ADV-2011-0997</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0986" source="VUPEN">ADV-2011-0986</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0936" source="VUPEN">ADV-2011-0936</ref>
      <ref url="http://www.securitytracker.com/id?1025320" source="SECTRACK">1025320</ref>
      <ref url="http://www.securityfocus.com/bid/47310" source="BID">47310</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0447.html" source="REDHAT">RHSA-2011:0447</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:077" source="MANDRIVA">MDVSA-2011:077</ref>
      <ref url="http://securityreason.com/securityalert/8200" source="SREASON">8200</ref>
      <ref url="http://secunia.com/advisories/44196" source="SECUNIA">44196</ref>
      <ref url="http://secunia.com/advisories/44181" source="SECUNIA">44181</ref>
      <ref url="http://secunia.com/advisories/44125" source="SECUNIA">44125</ref>
      <ref url="http://osvdb.org/71789" source="OSVDB">71789</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058181.html" source="FEDORA">FEDORA-2011-5333</ref>
      <ref url="http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899" source="CONFIRM">http://krbdev.mit.edu/rt/Ticket/Display.html?id=6899</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621726" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=621726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.7"/>
        <vers num="5-1.7.1"/>
        <vers num="5-1.8"/>
        <vers num="5-1.8.1"/>
        <vers num="5-1.8.2"/>
        <vers num="5-1.8.3"/>
        <vers num="5-1.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0286" published="2011-04-18" name="CVE-2011-0286" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject arbitrary web script or HTML via the displayErrorMessage parameter in a ManageDevices action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0971" source="VUPEN" adv="1">ADV-2011-0971</ref>
      <ref url="http://www.securityfocus.com/bid/47324" source="BID">47324</ref>
      <ref url="http://www.cybsec.com/vuln/CYBSEC_Advisory_2011_0401_Cross_Site_Scripting_XSS_in_Blackberry_WebDesktop.pdf" source="MISC">http://www.cybsec.com/vuln/CYBSEC_Advisory_2011_0401_Cross_Site_Scripting_XSS_in_Blackberry_WebDesktop.pdf</ref>
      <ref url="http://www.blackberry.com/btsc/KB26296" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/KB26296</ref>
      <ref url="http://securitytracker.com/id?1025356" source="SECTRACK">1025356</ref>
      <ref url="http://secunia.com/advisories/44183" source="SECUNIA" adv="1">44183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
      <prod vendor="rim" name="blackberry_enterprise_server_express">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0287" published="2011-07-14" name="CVE-2011-0287" modified="2011-07-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BlackBerry Administration API in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 5.0.1 through 5.0.3, and BlackBerry Enterprise Server Express software 5.0.1 through 5.0.3, allows remote attackers to read text files or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/48655" source="BID">48655</ref>
      <ref url="http://www.blackberry.com/btsc/KB27258" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/KB27258</ref>
      <ref url="http://secunia.com/advisories/45242" source="SECUNIA" adv="1">45242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
      <prod vendor="rim" name="blackberry_enterprise_server_express">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0290" published="2011-10-21" name="CVE-2011-0290" modified="2012-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/70519" source="XF">bes-collaboration-service-spoofing(70519)</ref>
      <ref url="http://www.securityfocus.com/bid/50064" source="BID">50064</ref>
      <ref url="http://www.osvdb.org/76286" source="OSVDB">76286</ref>
      <ref url="http://www.blackberry.com/btsc/KB28524" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/KB28524</ref>
      <ref url="http://securitytracker.com/id?1026179" source="SECTRACK">1026179</ref>
      <ref url="http://secunia.com/advisories/46370" source="SECUNIA" adv="1">46370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="5.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0291" published="2011-12-08" name="CVE-2011-0291" modified="2011-12-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/71659" source="XF">blackberry-playbook-priv-esc(71659)</ref>
      <ref url="http://www.securityfocus.com/bid/50931" source="BID">50931</ref>
      <ref url="http://securitytracker.com/id?1026386" source="SECTRACK">1026386</ref>
      <ref url="http://secunia.com/advisories/47132" source="SECUNIA" adv="1">47132</ref>
      <ref url="http://blackberry.com/btsc/KB29191" source="CONFIRM" adv="1">http://blackberry.com/btsc/KB29191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blackberry" name="blackberry_tablet_os">
        <vers num="1.0.8.4985"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0310" published="2011-01-13" name="CVE-2011-0310" modified="2011-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www-304.ibm.com/support/docview.wss?uid=swg1SE45551" source="AIXAPAR">IZ77607</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64628" source="XF">wmq-messageheader-bo(64628)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0128" source="VUPEN">ADV-2011-0128</ref>
      <ref url="http://www.securityfocus.com/bid/45923" source="BID">45923</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014224" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014224</ref>
      <ref url="http://secunia.com/advisories/42958" source="SECUNIA">42958</ref>
      <ref url="http://osvdb.org/70476" source="OSVDB">70476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.1.0"/>
        <vers num="7.0.1.1"/>
        <vers num="7.0.1.2"/>
        <vers num="7.0.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0311" published="2011-09-02" name="CVE-2011-0311" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551" source="AIXAPAR">PM42551</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65189" source="XF">ibm-rjt-classfile-dos(65189)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1265.html" source="REDHAT">RHSA-2011:1265</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-1159.html" source="REDHAT">RHSA-2011:1159</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89620" source="AIXAPAR">IZ89620</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602" source="AIXAPAR">IZ89602</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00010.html" source="SUSE">SUSE-SU-2011:0823</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00004.html" source="SUSE">SUSE-SA:2011:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="java">
        <vers num="1.4.2"/>
        <vers num="1.4.2.13"/>
        <vers num="1.4.2.13.1"/>
        <vers num="1.4.2.13.2"/>
        <vers num="1.4.2.13.3"/>
        <vers num="1.4.2.13.4"/>
        <vers num="1.4.2.13.5"/>
        <vers num="1.4.2.13.6"/>
        <vers num="1.4.2.13.7"/>
        <vers prev="1" num="1.4.2.13.8"/>
      </prod>
      <prod vendor="ibm" name="runtimes_for_java_technology">
        <vers num="5.0.0"/>
        <vers num="5.0.11.0"/>
        <vers num="5.0.11.1"/>
        <vers num="5.0.11.2"/>
        <vers num="5.0.12.0"/>
        <vers num="5.0.12.1"/>
        <vers num="5.0.12.2"/>
        <vers num="5.0.12.3"/>
        <vers prev="1" num="5.0.12.4"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1.0"/>
        <vers num="6.0.2.0"/>
        <vers num="6.0.3.0"/>
        <vers num="6.0.4.0"/>
        <vers num="6.0.5.0"/>
        <vers num="6.0.6.0"/>
        <vers num="6.0.7.0"/>
        <vers num="6.0.8.0"/>
        <vers num="6.0.8.1"/>
        <vers prev="1" num="6.0.9.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0314" published="2011-01-11" name="CVE-2011-0314" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64550" source="XF">wmq-message-bo(64550)</ref>
      <ref url="http://www.securityfocus.com/bid/45801" source="BID">45801</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ81294" source="AIXAPAR">IZ81294</ref>
      <ref url="http://secunia.com/advisories/42941" source="SECUNIA">42941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="6.0"/>
        <vers num="6.0.1.0"/>
        <vers num="6.0.1.1"/>
        <vers num="6.0.2.0"/>
        <vers num="6.0.2.1"/>
        <vers num="6.0.2.10"/>
        <vers num="6.0.2.2"/>
        <vers num="6.0.2.3"/>
        <vers num="6.0.2.4"/>
        <vers num="6.0.2.5"/>
        <vers num="6.0.2.6"/>
        <vers num="6.0.2.7"/>
        <vers num="6.0.2.8"/>
        <vers num="6.0.2.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.1"/>
        <vers num="7.0.1.0"/>
        <vers num="7.0.1.1"/>
        <vers num="7.0.1.2"/>
        <vers num="7.0.1.3"/>
        <vers num="7.0.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0315" published="2011-01-11" name="CVE-2011-0315" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Servlet Engine / Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to the lack of an error page for an application.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64554" source="XF">was-webcontainer-xss(64554)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0564" source="VUPEN">ADV-2011-0564</ref>
      <ref url="http://www.securityfocus.com/bid/46736" source="BID">46736</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM18512" source="AIXAPAR">PM18512</ref>
      <ref url="http://secunia.com/advisories/42938" source="SECUNIA">42938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0316" published="2011-01-11" name="CVE-2011-0316" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict access to console servlets, which allows remote attackers to obtain potentially sensitive status information via a direct request.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64558" source="XF">was-consoleservlet-info-disclosure(64558)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0564" source="VUPEN">ADV-2011-0564</ref>
      <ref url="http://www.securityfocus.com/bid/46736" source="BID">46736</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PM24372" source="AIXAPAR">PM24372</ref>
      <ref url="http://secunia.com/advisories/42938" source="SECUNIA">42938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1"/>
        <vers num="6.1.0"/>
        <vers num="6.1.0.0"/>
        <vers num="6.1.0.1"/>
        <vers num="6.1.0.11"/>
        <vers num="6.1.0.12"/>
        <vers num="6.1.0.13"/>
        <vers num="6.1.0.15"/>
        <vers num="6.1.0.17"/>
        <vers num="6.1.0.19"/>
        <vers num="6.1.0.2"/>
        <vers num="6.1.0.21"/>
        <vers num="6.1.0.23"/>
        <vers num="6.1.0.25"/>
        <vers num="6.1.0.27"/>
        <vers num="6.1.0.29"/>
        <vers num="6.1.0.3"/>
        <vers num="6.1.0.31"/>
        <vers num="6.1.0.33"/>
        <vers num="6.1.0.5"/>
        <vers num="6.1.0.7"/>
        <vers num="6.1.0.9"/>
        <vers num="7.0"/>
        <vers num="7.0.0.1"/>
        <vers num="7.0.0.11"/>
        <vers num="7.0.0.13"/>
        <vers num="7.0.0.2"/>
        <vers num="7.0.0.3"/>
        <vers num="7.0.0.4"/>
        <vers num="7.0.0.5"/>
        <vers num="7.0.0.6"/>
        <vers num="7.0.0.7"/>
        <vers num="7.0.0.8"/>
        <vers num="7.0.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0317" published="2011-06-16" name="CVE-2011-0317" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-166A.html" source="CERT">TA11-166A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb11-17.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb11-17.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0"/>
        <vers num="10.0.0.210"/>
        <vers num="10.0.1.004"/>
        <vers num="10.1.0.011"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.1.016"/>
        <vers num="10.1.4.020"/>
        <vers num="10.2.0.021"/>
        <vers num="10.2.0.022"/>
        <vers num="10.2.0.023"/>
        <vers num="11.0.0.456"/>
        <vers num="11.0.3.471"/>
        <vers num="11.5.0.595"/>
        <vers num="11.5.0.596"/>
        <vers num="11.5.1.601"/>
        <vers num="11.5.2.602"/>
        <vers num="11.5.6.606"/>
        <vers num="11.5.7.609"/>
        <vers num="11.5.8.612"/>
        <vers num="11.5.9.615"/>
        <vers prev="1" num="11.5.9.620"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="8.0"/>
        <vers num="8.0.196"/>
        <vers num="8.0.196a"/>
        <vers num="8.0.204"/>
        <vers num="8.0.205"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.100"/>
        <vers num="8.5.1.103"/>
        <vers num="8.5.1.105"/>
        <vers num="8.5.1.106"/>
        <vers num="8.5.321"/>
        <vers num="8.5.323"/>
        <vers num="8.5.324"/>
        <vers num="8.5.325"/>
        <vers num="9"/>
        <vers num="9.0.383"/>
        <vers num="9.0.432"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0318" published="2011-06-16" name="CVE-2011-0318" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0319, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-166A.html" source="CERT">TA11-166A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb11-17.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb11-17.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0"/>
        <vers num="10.0.0.210"/>
        <vers num="10.0.1.004"/>
        <vers num="10.1.0.011"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.1.016"/>
        <vers num="10.1.4.020"/>
        <vers num="10.2.0.021"/>
        <vers num="10.2.0.022"/>
        <vers num="10.2.0.023"/>
        <vers num="11.0.0.456"/>
        <vers num="11.0.3.471"/>
        <vers num="11.5.0.595"/>
        <vers num="11.5.0.596"/>
        <vers num="11.5.1.601"/>
        <vers num="11.5.2.602"/>
        <vers num="11.5.6.606"/>
        <vers num="11.5.7.609"/>
        <vers num="11.5.8.612"/>
        <vers num="11.5.9.615"/>
        <vers prev="1" num="11.5.9.620"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="8.0"/>
        <vers num="8.0.196"/>
        <vers num="8.0.196a"/>
        <vers num="8.0.204"/>
        <vers num="8.0.205"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.100"/>
        <vers num="8.5.1.103"/>
        <vers num="8.5.1.105"/>
        <vers num="8.5.1.106"/>
        <vers num="8.5.321"/>
        <vers num="8.5.323"/>
        <vers num="8.5.324"/>
        <vers num="8.5.325"/>
        <vers num="9"/>
        <vers num="9.0.383"/>
        <vers num="9.0.432"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0319" published="2011-06-16" name="CVE-2011-0319" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0320, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-166A.html" source="CERT">TA11-166A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb11-17.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb11-17.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0"/>
        <vers num="10.0.0.210"/>
        <vers num="10.0.1.004"/>
        <vers num="10.1.0.011"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.1.016"/>
        <vers num="10.1.4.020"/>
        <vers num="10.2.0.021"/>
        <vers num="10.2.0.022"/>
        <vers num="10.2.0.023"/>
        <vers num="11.0.0.456"/>
        <vers num="11.0.3.471"/>
        <vers num="11.5.0.595"/>
        <vers num="11.5.0.596"/>
        <vers num="11.5.1.601"/>
        <vers num="11.5.2.602"/>
        <vers num="11.5.6.606"/>
        <vers num="11.5.7.609"/>
        <vers num="11.5.8.612"/>
        <vers num="11.5.9.615"/>
        <vers prev="1" num="11.5.9.620"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="8.0"/>
        <vers num="8.0.196"/>
        <vers num="8.0.196a"/>
        <vers num="8.0.204"/>
        <vers num="8.0.205"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.100"/>
        <vers num="8.5.1.103"/>
        <vers num="8.5.1.105"/>
        <vers num="8.5.1.106"/>
        <vers num="8.5.321"/>
        <vers num="8.5.323"/>
        <vers num="8.5.324"/>
        <vers num="8.5.325"/>
        <vers num="9"/>
        <vers num="9.0.383"/>
        <vers num="9.0.432"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0320" published="2011-06-16" name="CVE-2011-0320" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0335, CVE-2011-2119, and CVE-2011-2122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-166A.html" source="CERT">TA11-166A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb11-17.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb11-17.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0"/>
        <vers num="10.0.0.210"/>
        <vers num="10.0.1.004"/>
        <vers num="10.1.0.011"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.1.016"/>
        <vers num="10.1.4.020"/>
        <vers num="10.2.0.021"/>
        <vers num="10.2.0.022"/>
        <vers num="10.2.0.023"/>
        <vers num="11.0.0.456"/>
        <vers num="11.0.3.471"/>
        <vers num="11.5.0.595"/>
        <vers num="11.5.0.596"/>
        <vers num="11.5.1.601"/>
        <vers num="11.5.2.602"/>
        <vers num="11.5.6.606"/>
        <vers num="11.5.7.609"/>
        <vers num="11.5.8.612"/>
        <vers num="11.5.9.615"/>
        <vers prev="1" num="11.5.9.620"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="8.0"/>
        <vers num="8.0.196"/>
        <vers num="8.0.196a"/>
        <vers num="8.0.204"/>
        <vers num="8.0.205"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.100"/>
        <vers num="8.5.1.103"/>
        <vers num="8.5.1.105"/>
        <vers num="8.5.1.106"/>
        <vers num="8.5.321"/>
        <vers num="8.5.323"/>
        <vers num="8.5.324"/>
        <vers num="8.5.325"/>
        <vers num="9"/>
        <vers num="9.0.383"/>
        <vers num="9.0.432"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0321" published="2011-02-01" name="CVE-2011-0321" modified="2011-02-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or obtain sensitive information from interprocess communication, via crafted UDP packets containing service commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64997" source="XF">networker-librpc-security-bypass(64997)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0241" source="VUPEN" adv="1">ADV-2011-0241</ref>
      <ref url="http://www.securityfocus.com/bid/46044" source="BID">46044</ref>
      <ref url="http://www.osvdb.org/70686" source="OSVDB">70686</ref>
      <ref url="http://securitytracker.com/id?1025010" source="SECTRACK">1025010</ref>
      <ref url="http://secunia.com/advisories/43113" source="SECUNIA" adv="1">43113</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2011-01/att-0162/ESA-2011-003.txt" source="CONFIRM">http://archives.neohapsis.com/archives/bugtraq/2011-01/att-0162/ESA-2011-003.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2011-01/0162.html" source="BUGTRAQ">20110126 ESA-2011-003: EMC NetWorker librpc.dll spoofing vulnerability.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="networker">
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="7.0"/>
        <vers num="7.2"/>
        <vers num="7.3"/>
        <vers num="7.4" edition="sp1"/>
        <vers num="7.4" edition="sp2"/>
        <vers num="7.4" edition="sp3"/>
        <vers num="7.4" edition="sp4"/>
        <vers num="7.4" edition="sp5"/>
        <vers prev="1" num="7.5" edition="sp1"/>
        <vers prev="1" num="7.5" edition="sp2"/>
        <vers prev="1" num="7.5" edition="sp3"/>
        <vers num="7.5.3.1"/>
        <vers num="7.5.3.2"/>
        <vers num="7.5.3.3"/>
        <vers num="7.5.3.4"/>
        <vers num="7.6.0.2"/>
        <vers num="7.6.0.3"/>
        <vers num="7.6.0.4"/>
        <vers num="7.6.0.5"/>
        <vers num="7.6.0.6"/>
        <vers num="7.6.0.7"/>
        <vers num="7.6.0.8"/>
        <vers num="7.6.0.9"/>
        <vers num="7.6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0322" published="2011-03-16" name="CVE-2011-0322" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in EMC RSA Access Manager Server 5.5.x, 6.0.x, and 6.1.x allows remote attackers to access resources via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/66104" source="XF">rsa-unspecified-security-bypass(66104)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0676" source="VUPEN">ADV-2011-0676</ref>
      <ref url="http://www.securitytracker.com/id?1025214" source="SECTRACK">1025214</ref>
      <ref url="http://www.securityfocus.com/bid/46875" source="BID">46875</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/517023/100/0/threaded" source="BUGTRAQ">20110315 ESA-2011-009: RSA, The Security Division of EMC, announces a fix for potential security vulnerability in RSA Access Manager Server</ref>
      <ref url="http://securityreason.com/securityalert/8142" source="SREASON">8142</ref>
      <ref url="http://secunia.com/advisories/43796" source="SECUNIA">43796</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rsa" name="access_manager_server">
        <vers num="5.5.3"/>
        <vers num="6.0.4"/>
        <vers num="6.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0323" published="2011-02-07" name="CVE-2011-0323" modified="2011-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65117" source="XF">sigplus-sigmessage-file-overwrite(65117)</ref>
      <ref url="http://www.securityfocus.com/bid/46128" source="BID">46128</ref>
      <ref url="http://secunia.com/secunia_research/2011-1/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-1/</ref>
      <ref url="http://secunia.com/advisories/42800" source="SECUNIA" adv="1">42800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topazsystems" name="sigplus_pro_activex_control">
        <vers num="3.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0324" published="2011-02-07" name="CVE-2011-0324" modified="2011-02-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the SetTabletPortPath method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65116" source="XF">sigplus-newportpath-bo(65116)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65115" source="XF">sigplus-newpath-bo(65115)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/65114" source="XF">sigplus-keystring-bo(65114)</ref>
      <ref url="http://www.securityfocus.com/bid/46128" source="BID">46128</ref>
      <ref url="http://secunia.com/secunia_research/2011-2/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-2/</ref>
      <ref url="http://secunia.com/advisories/42800" source="SECUNIA" adv="1">42800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topazsystems" name="sigplus_pro_activex_control">
        <vers num="3.95"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0329" published="2011-02-21" name="CVE-2011-0329" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025094" source="SECTRACK">1025094</ref>
      <ref url="http://www.securityfocus.com/bid/46443" source="BID">46443</ref>
      <ref url="http://secunia.com/secunia_research/2011-10/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-10/</ref>
      <ref url="http://secunia.com/advisories/42880" source="SECUNIA" adv="1">42880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dell" name="dellsystemlite.scanner_activex_control">
        <vers num="1.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0330" published="2011-02-21" name="CVE-2011-0330" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of information about installed software.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025094" source="SECTRACK">1025094</ref>
      <ref url="http://www.securityfocus.com/bid/46443" source="BID">46443</ref>
      <ref url="http://secunia.com/secunia_research/2011-11/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-11/</ref>
      <ref url="http://secunia.com/advisories/42880" source="SECUNIA" adv="1">42880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dell" name="dellsystemlite.scanner_activex_control">
        <vers num="1.0.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0331" published="2011-03-22" name="CVE-2011-0331" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0725" source="VUPEN">ADV-2011-0725</ref>
      <ref url="http://www.securityfocus.com/bid/46930" source="BID">46930</ref>
      <ref url="http://secunia.com/secunia_research/2011-22/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-22/</ref>
      <ref url="http://secunia.com/advisories/43360" source="SECUNIA" adv="1">43360</ref>
      <ref url="http://osvdb.org/71249" source="OSVDB">71249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="honeywell" name="scanserver_activex_control">
        <vers num="780.0.20.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0332" published="2011-02-25" name="CVE-2011-0332" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Foxit Reader before 4.3.1.0218 and Foxit Phantom before 2.3.3.1112 allows remote attackers to execute arbitrary code via crafted ICC chunks in a PDF file, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security_bulletins.php#memory" source="CONFIRM" patch="1">http://www.foxitsoftware.com/pdf/reader/security_bulletins.php#memory</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0508" source="VUPEN" adv="1">ADV-2011-0508</ref>
      <ref url="http://www.securitytracker.com/id?1025129" source="SECTRACK">1025129</ref>
      <ref url="http://secunia.com/secunia_research/2011-14/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-14/</ref>
      <ref url="http://secunia.com/advisories/43440" source="SECUNIA" adv="1">43440</ref>
      <ref url="http://secunia.com/advisories/43329" source="SECUNIA" adv="1">43329</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="phantom">
        <vers num="1.0.2"/>
        <vers num="2.0"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.2"/>
        <vers num="2.2.1"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers prev="1" num="2.3"/>
      </prod>
      <prod vendor="foxitsoftware" name="reader">
        <vers num="2.0"/>
        <vers num="2.2"/>
        <vers num="2.3"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1.1"/>
        <vers num="3.1.3"/>
        <vers num="3.1.4"/>
        <vers num="3.2"/>
        <vers num="3.2.1"/>
        <vers num="3.3.1"/>
        <vers num="4.0"/>
        <vers num="4.1.1"/>
        <vers prev="1" num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0333" published="2011-10-07" name="CVE-2011-0333" modified="2012-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://labs.idefense.com/verisign/intelligence/2009/vulnerabilities/display.php?id=943" source="IDEFENSE">20110926 Novell GroupWise iCal TZNAME Heap Overflow Vulnerability</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=678715" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=678715</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7009208" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7009208</ref>
      <ref url="http://secunia.com/secunia_research/2011-66/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-66/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="8.0" edition="hp1"/>
        <vers num="8.0" edition="hp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0334" published="2011-10-07" name="CVE-2011-0334" modified="2012-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=678939" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=678939</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7009210" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7009210</ref>
      <ref url="http://secunia.com/secunia_research/2011-67/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-67/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="8.0" edition="hp1"/>
        <vers num="8.0" edition="hp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0335" published="2011-06-16" name="CVE-2011-0335" modified="2011-10-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Dirapi.dll in Adobe Shockwave Player before 11.6.0.626 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0317, CVE-2011-0318, CVE-2011-0319, CVE-2011-0320, CVE-2011-2119, and CVE-2011-2122.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-166A.html" source="CERT">TA11-166A</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb11-17.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb11-17.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="shockwave_player">
        <vers num="1.0"/>
        <vers num="10.0.0.210"/>
        <vers num="10.0.1.004"/>
        <vers num="10.1.0.011"/>
        <vers num="10.1.0.11"/>
        <vers num="10.1.1.016"/>
        <vers num="10.1.4.020"/>
        <vers num="10.2.0.021"/>
        <vers num="10.2.0.022"/>
        <vers num="10.2.0.023"/>
        <vers num="11.0.0.456"/>
        <vers num="11.0.3.471"/>
        <vers num="11.5.0.595"/>
        <vers num="11.5.0.596"/>
        <vers num="11.5.1.601"/>
        <vers num="11.5.2.602"/>
        <vers num="11.5.6.606"/>
        <vers num="11.5.7.609"/>
        <vers num="11.5.8.612"/>
        <vers num="11.5.9.615"/>
        <vers prev="1" num="11.5.9.620"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="4.0"/>
        <vers num="5.0"/>
        <vers num="6.0"/>
        <vers num="8.0"/>
        <vers num="8.0.196"/>
        <vers num="8.0.196a"/>
        <vers num="8.0.204"/>
        <vers num="8.0.205"/>
        <vers num="8.5.1"/>
        <vers num="8.5.1.100"/>
        <vers num="8.5.1.103"/>
        <vers num="8.5.1.105"/>
        <vers num="8.5.1.106"/>
        <vers num="8.5.321"/>
        <vers num="8.5.323"/>
        <vers num="8.5.324"/>
        <vers num="8.5.325"/>
        <vers num="9"/>
        <vers num="9.0.383"/>
        <vers num="9.0.432"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0340" published="2011-05-04" name="CVE-2011-0340" modified="2013-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/1116" source="VUPEN" adv="1">ADV-2011-1116</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/1115" source="VUPEN" adv="1">ADV-2011-1115</ref>
      <ref url="http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf" source="MISC">http://www.us-cert.gov/control_systems/pdf/ICSA-12-137-02.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/47596" source="BID">47596</ref>
      <ref url="http://www.indusoft.com/hotfixes/hotfixes.php" source="CONFIRM">http://www.indusoft.com/hotfixes/hotfixes.php</ref>
      <ref url="http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm" source="CONFIRM">http://www.advantechdirect.com/eMarketingPrograms/AStudio_Patch/AStudio7.0_Patch_Final.htm</ref>
      <ref url="http://secunia.com/secunia_research/2011-37/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-37/</ref>
      <ref url="http://secunia.com/secunia_research/2011-36/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-36/</ref>
      <ref url="http://secunia.com/advisories/43116" source="SECUNIA" adv="1">43116</ref>
      <ref url="http://secunia.com/advisories/42928" source="SECUNIA" adv="1">42928</ref>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03" source="MISC">http://ics-cert.us-cert.gov/advisories/ICSA-12-249-03</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantech" name="advantech_studio">
        <vers num="6.1" edition="sp6_61.6.01.05"/>
      </prod>
      <prod vendor="indusoft" name="thin_client">
        <vers num="7.0"/>
      </prod>
      <prod vendor="indusoft" name="web_studio">
        <vers num="6.1" edition="sp6"/>
        <vers prev="1" num="7.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0341" published="2011-05-13" name="CVE-2011-0341" modified="2011-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/67298" source="XF">mupdf-pdfmozonmouse-bo(67298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/1191" source="VUPEN" adv="1">ADV-2011-1191</ref>
      <ref url="http://www.securityfocus.com/bid/47739" source="BID">47739</ref>
      <ref url="http://www.osvdb.org/72177" source="OSVDB">72177</ref>
      <ref url="http://secunia.com/secunia_research/2011-38/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-38/</ref>
      <ref url="http://secunia.com/advisories/43739" source="SECUNIA" adv="1">43739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="artifex" name="mupdf">
        <vers num="2008.09.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0342" published="2011-09-02" name="CVE-2011-0342" modified="2013-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCurrentLanguage method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/49403" source="BID">49403</ref>
      <ref url="http://www.indusoft.com/hotfixes/hotfixes.php" source="CONFIRM">http://www.indusoft.com/hotfixes/hotfixes.php</ref>
      <ref url="http://secunia.com/secunia_research/2011-61/" source="MISC" adv="1">http://secunia.com/secunia_research/2011-61/</ref>
      <ref url="http://secunia.com/advisories/44875" source="SECUNIA" adv="1">44875</ref>
      <ref url="http://ics-cert.us-cert.gov/advisories/ICSA-11-273-02" source="MISC">http://ics-cert.us-cert.gov/advisories/ICSA-11-273-02</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indusoft" name="web_studio">
        <vers num="7.0b2" edition="hotfix7.0.01.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0343" published="2011-01-28" name="CVE-2011-0343" modified="2011-02-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to create log files with insecure permissions (07777), which allows local users to read and write to these log files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608491" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=608491</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.2.1a has been released</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.0.6a has been released</ref>
      <ref url="http://www.securityfocus.com/bid/45988" source="BID">45988</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515955/100/0/threaded" source="BUGTRAQ">20110125 syslog-ng wrong file permission vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="balabit" name="syslog-ng">
        <vers num="2.0" edition=""/>
        <vers num="2.0" edition=":premium"/>
        <vers num="2.0" edition=":open_source"/>
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":open_source"/>
        <vers num="3.0" edition=":premium"/>
        <vers num="3.1" edition=""/>
        <vers num="3.1" edition=":open_source"/>
        <vers num="3.1" edition=":premium"/>
        <vers num="3.2" edition=""/>
        <vers num="3.2" edition=":premium"/>
        <vers num="3.2" edition=":open_source"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0344" published="2011-03-08" name="CVE-2011-0344" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.5" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65849" source="XF">omnipcx-unified-maintenance-bo(65849)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0549" source="VUPEN" adv="1">ADV-2011-0549</ref>
      <ref url="http://www.securityfocus.com/bid/46640" source="BID">46640</ref>
      <ref url="http://www.alcatel-lucent.com/wps/DocumentStreamerServlet?LMSG_CABINET=Corporate&amp;LMSG_CONTENT_FILE=Support/Security/2011001.pdf" source="CONFIRM" adv="1">http://www.alcatel-lucent.com/wps/DocumentStreamerServlet?LMSG_CABINET=Corporate&amp;LMSG_CONTENT_FILE=Support/Security/2011001.pdf</ref>
      <ref url="http://secunia.com/advisories/43588" source="SECUNIA" adv="1">43588</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=896" source="IDEFENSE">20110301 Alcatel-Lucent OmniPCX Enterprise CS CGI Cookie Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="omnipcx">
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":enterprise"/>
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":enterprise"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":enterprise"/>
        <vers num="7.1" edition=""/>
        <vers num="7.1" edition=":enterprise"/>
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":enterprise"/>
        <vers prev="1" num="9.0" edition=""/>
        <vers prev="1" num="9.0" edition=":enterprise"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2011-0345" published="2011-03-08" name="CVE-2011-0345" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the NMS server in Alcatel-Lucent OmniVista 4760 R5.1.06.03 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in HTTP GET requests, related to the lang variable.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65848" source="XF">omnivista-lang-file-include(65848)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0548" source="VUPEN" adv="1">ADV-2011-0548</ref>
      <ref url="http://www.securityfocus.com/bid/46624" source="BID">46624</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516768/100/0/threaded" source="BUGTRAQ">20110301 DDIVRT-2010-30 Alcatel-Lucent OmniVista 4760 NMS 'lang' Directory Traversal Vulnerability [ CVE-2011-0345 ]</ref>
      <ref url="http://www.alcatel-lucent.com/wps/DocumentStreamerServlet?LMSG_CABINET=Corporate&amp;LMSG_CONTENT_FILE=Support/Security/2011002.pdf" source="CONFIRM" adv="1">http://www.alcatel-lucent.com/wps/DocumentStreamerServlet?LMSG_CABINET=Corporate&amp;LMSG_CONTENT_FILE=Support/Security/2011002.pdf</ref>
      <ref url="http://securityreason.com/securityalert/8122" source="SREASON">8122</ref>
      <ref url="http://secunia.com/advisories/43507" source="SECUNIA" adv="1">43507</ref>
      <ref url="http://seclists.org/fulldisclosure/2011/Mar/8" source="FULLDISC">20110301 DDIVRT-2010-30 Alcatel-Lucent OmniVista 4760 NMS 'lang' Directory Traversal Vulnerability [ CVE-2011-0345 ]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alcatel-lucent" name="omnivista">
        <vers num="4760_r5.0.07.05"/>
        <vers prev="1" num="4760_r5.1.06.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0346" published="2011-01-07" name="CVE-2011-0346" modified="2011-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA11-102A.html" source="CERT">TA11-102A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/427980" source="CERT-VN">VU#427980</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS11-018.mspx" source="MS" patch="1" adv="1">MS11-018</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64482" source="XF">ms-ie-releaseinterface-code-execution(64482)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0026" source="VUPEN" adv="1">ADV-2011-0026</ref>
      <ref url="http://www.securitytracker.com/id?1024940" source="SECTRACK">1024940</ref>
      <ref url="http://www.securityfocus.com/bid/45639" source="BID">45639</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515506/100/0/threaded" source="BUGTRAQ">20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11882" source="OVAL">oval:org.mitre.oval:def:11882</ref>
      <ref url="http://lcamtuf.coredump.cx/cross_fuzz/msie_crash.txt" source="MISC">http://lcamtuf.coredump.cx/cross_fuzz/msie_crash.txt</ref>
      <ref url="http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt" source="MISC">http://lcamtuf.coredump.cx/cross_fuzz/known_vuln.txt</ref>
      <ref url="http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt" source="MISC">http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt</ref>
      <ref url="http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html" source="MISC">http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html</ref>
      <ref url="http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx" source="MISC">http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html" source="FULLDISC">20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6"/>
        <vers num="7"/>
        <vers num="8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0347" published="2011-01-07" name="CVE-2011-0347" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via vectors related to the DOM implementation, as demonstrated by cross_fuzz.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64571" source="XF">ms-ie-gui-weak-security(64571)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515506/100/0/threaded" source="BUGTRAQ">20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/2490606.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/2490606.mspx</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12514" source="OVAL">oval:org.mitre.oval:def:12514</ref>
      <ref url="http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg" source="MISC">http://lcamtuf.coredump.cx/cross_fuzz/msie_display.jpg</ref>
      <ref url="http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt" source="MISC">http://lcamtuf.coredump.cx/cross_fuzz/fuzzer_timeline.txt</ref>
      <ref url="http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html" source="MISC">http://lcamtuf.blogspot.com/2011/01/announcing-crossfuzz-potential-0-day-in.html</ref>
      <ref url="http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx" source="MISC">http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0698.html" source="FULLDISC">20110101 Announcing cross_fuzz, a potential 0-day in circulation, and more</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0348" published="2011-01-28" name="CVE-2011-0348" modified="2011-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64936" source="XF">cisco-csg2-policy-security-bypass(64936)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0229" source="VUPEN">ADV-2011-0229</ref>
      <ref url="http://www.securityfocus.com/bid/46022" source="BID">46022</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml" source="CISCO" adv="1">20110126 Cisco Content Services Gateway Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024992" source="SECTRACK">1024992</ref>
      <ref url="http://secunia.com/advisories/43052" source="SECUNIA" adv="1">43052</ref>
      <ref url="http://osvdb.org/70720" source="OSVDB">70720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4(11)md"/>
        <vers num="12.4(15)md"/>
        <vers num="12.4(22)md"/>
        <vers num="12.4(22)mda"/>
        <vers num="12.4(24)md"/>
        <vers num="12.4(24)md1"/>
        <vers num="12.4(24)mda"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0349" published="2011-01-28" name="CVE-2011-0349" modified="2011-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth17178, a different vulnerability than CVE-2011-0350.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64937" source="XF">cisco-csg2-tcp-dos(64937)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0229" source="VUPEN">ADV-2011-0229</ref>
      <ref url="http://www.securityfocus.com/bid/46026" source="BID">46026</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml" source="CISCO" adv="1">20110126 Cisco Content Services Gateway Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024992" source="SECTRACK">1024992</ref>
      <ref url="http://secunia.com/advisories/43052" source="SECUNIA" adv="1">43052</ref>
      <ref url="http://osvdb.org/70721" source="OSVDB">70721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4(24)md"/>
        <vers num="12.4(24)md1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0350" published="2011-01-28" name="CVE-2011-0350" modified="2011-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth41891, a different vulnerability than CVE-2011-0349.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/64938" source="XF">cisco-csg2-tcp-packets-dos(64938)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0229" source="VUPEN">ADV-2011-0229</ref>
      <ref url="http://www.securityfocus.com/bid/46028" source="BID">46028</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6791d.shtml" source="CISCO" adv="1">20110126 Cisco Content Services Gateway Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1024992" source="SECTRACK">1024992</ref>
      <ref url="http://secunia.com/advisories/43052" source="SECUNIA" adv="1">43052</ref>
      <ref url="http://osvdb.org/70722" source="OSVDB">70722</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4(24)md"/>
        <vers num="12.4(24)md1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0352" published="2011-01-24" name="CVE-2011-0352" modified="2011-02-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in the web-based management interface on the Cisco Linksys WRT54GC router with firmware before 1.06.1 allows remote attackers to cause a denial of service (device crash) via a long string in a POST request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=22228" source="CONFIRM" patch="1" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=22228</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64850" source="XF">wrt54gc-interface-bo(64850)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0205" source="VUPEN">ADV-2011-0205</ref>
      <ref url="http://secunia.com/advisories/43017" source="SECUNIA" adv="1">43017</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2011/JVNDB-2011-000007.html" source="JVNDB">JVNDB-2011-000007</ref>
      <ref url="http://jvn.jp/en/jp/JVN26605630/index.html" source="JVN">JVN#26605630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="linksys_wrt54gc_router_firmware">
        <vers num="1.02.5"/>
        <vers num="1.02.8"/>
        <vers prev="1" num="1.05.7"/>
      </prod>
      <prod vendor="cisco" name="linksys_wrt54gc_router">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0354" published="2011-02-03" name="CVE-2011-0354" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/436854" source="CERT-VN">VU#436854</ref>
      <ref url="http://www.securityfocus.com/bid/46107" source="BID">46107</ref>
      <ref url="http://www.exploit-db.com/exploits/16100" source="EXPLOIT-DB">16100</ref>
      <ref url="http://www.cisco.com/en/US/products/ps11422/products_security_advisory09186a0080b69541.shtml" source="CISCO" adv="1">20110202 Default Credentials for Root Account on Tandberg E, EX and C Series Endpoints</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=22314" source="CONFIRM">http://tools.cisco.com/security/center/viewAlert.x?alertId=22314</ref>
      <ref url="http://securitytracker.com/id?1025017" source="SECTRACK">1025017</ref>
      <ref url="http://securityreason.com/securityalert/8060" source="SREASON">8060</ref>
      <ref url="http://secunia.com/advisories/43158" source="SECUNIA" adv="1">43158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="tandberg_endpoint">
        <vers num="tc2.1.2"/>
        <vers num="tc3.0.0"/>
        <vers num="tc3.1.0"/>
        <vers num="tc3.1.1"/>
        <vers num="tc3.1.2"/>
        <vers prev="1" num="tc3.1.3"/>
      </prod>
      <prod vendor="cisco" name="tandberg_personal_video_unit_software">
        <vers num="tc3.1.0"/>
        <vers num="tc3.1.1"/>
        <vers num="tc3.1.2"/>
        <vers prev="1" num="tc3.1.3"/>
        <vers num="te1.0.1"/>
        <vers num="te2.2.0"/>
        <vers prev="1" num="te2.2.1"/>
      </prod>
      <prod vendor="cisco" name="tandberg_endpoint">
        <vers num="c20"/>
        <vers num="c40"/>
        <vers num="c60"/>
        <vers num="c90"/>
      </prod>
      <prod vendor="cisco" name="tandberg_personal_video_unit">
        <vers num="e20"/>
        <vers num="ex60"/>
        <vers num="ex90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0355" published="2011-02-17" name="CVE-2011-0355" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Nexus 1000V Virtual Ethernet Module (VEM) 4.0(4) SV1(1) through SV1(3b), as used in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, does not properly handle dropped packets, which allows guest OS users to cause a denial of service (ESX or ESXi host OS crash) by sending an 802.1Q tagged packet over an access vEthernet port, aka Cisco Bug ID CSCtj17451.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65217" source="XF">cisco-nexus-packets-dos(65217)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0315" source="VUPEN" adv="1">ADV-2011-0315</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0314" source="VUPEN" adv="1">ADV-2011-0314</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0002.html" source="CONFIRM" adv="1">http://www.vmware.com/security/advisories/VMSA-2011-0002.html</ref>
      <ref url="http://www.securityfocus.com/bid/46247" source="BID">46247</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516259/100/0/threaded" source="BUGTRAQ">20110208 VMSA-2011-0002 Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi</ref>
      <ref url="http://www.osvdb.org/70837" source="OSVDB">70837</ref>
      <ref url="http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_0_4_s_v_1_3_c/release/notes/n1000v_rn.html" source="CONFIRM">http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_0_4_s_v_1_3_c/release/notes/n1000v_rn.html</ref>
      <ref url="http://securitytracker.com/id?1025030" source="SECTRACK">1025030</ref>
      <ref url="http://securityreason.com/securityalert/8090" source="SREASON">8090</ref>
      <ref url="http://secunia.com/advisories/43084" source="SECUNIA" adv="1">43084</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2011/000118.html" source="MLIST">[security-announce] 20110207 VMSA-2011-0002 Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="1000v_virtual_ethernet_module_(vem)">
        <vers num="4.0(4)" edition="sv1(1)"/>
        <vers num="4.0(4)" edition="sv1(2)"/>
        <vers num="4.0(4)" edition="sv1(3)"/>
        <vers num="4.0(4)" edition="sv1(3a)"/>
        <vers num="4.0(4)" edition="sv1(3b)"/>
      </prod>
      <prod vendor="vmware" name="esx">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
      <prod vendor="vmware" name="esxi">
        <vers num="4.0"/>
        <vers num="4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0364" published="2011-02-18" name="CVE-2011-0364" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65436" source="XF">cisco-security-webagent-file-upload(65436)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-11-088" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-11-088</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0424" source="VUPEN" adv="1">ADV-2011-0424</ref>
      <ref url="http://www.securitytracker.com/id?1025088" source="SECTRACK">1025088</ref>
      <ref url="http://www.securityfocus.com/bid/46420" source="BID">46420</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516505/100/0/threaded" source="BUGTRAQ">20110217 ZDI-11-088: Cisco Security Agent Management st_upload Remote Code Execution Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6cee6.shtml" source="CISCO" adv="1">20110216 Management Center for Cisco Security Agent Remote Code Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/8205" source="SREASON">8205</ref>
      <ref url="http://securityreason.com/securityalert/8197" source="SREASON">8197</ref>
      <ref url="http://securityreason.com/securityalert/8095" source="SREASON">8095</ref>
      <ref url="http://secunia.com/advisories/43393" source="SECUNIA" adv="1">43393</ref>
      <ref url="http://secunia.com/advisories/43383" source="SECUNIA" adv="1">43383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="security_agent">
        <vers num="5.1"/>
        <vers num="5.2"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0372" published="2011-02-25" name="CVE-2011-0372" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0373" published="2011-02-25" name="CVE-2011-0373" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31685.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0374" published="2011-02-25" name="CVE-2011-0374" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0375" published="2011-02-25" name="CVE-2011-0375" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0376" published="2011-02-25" name="CVE-2011-0376" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain sensitive information via a GET request, aka Bug ID CSCte43876.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0377" published="2011-02-25" name="CVE-2011-0377" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65616" source="XF">cisco-endpoint-ipaddress-dos(65616)</ref>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0378" published="2011-02-25" name="CVE-2011-0378" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="8.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.5" CVSS_base_score="8.3">
    <desc>
      <descript source="cve">The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0379" published="2011-02-25" name="CVE-2011-0379" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="7.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="5.5" CVSS_base_score="7.9">
    <desc>
      <descript source="cve">Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x, 1.4.x, 1.5.x, and 1.6.2 allows remote attackers to execute arbitrary code via a crafted Cisco Discovery Protocol packet, aka Bug IDs CSCtd75769, CSCtd75766, CSCtd75754, and CSCtd75761.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securitytracker.com/id?1025112" source="SECTRACK">1025112</ref>
      <ref url="http://www.securitytracker.com/id?1025111" source="SECTRACK">1025111</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e152.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Manager</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="1.6.0"/>
      </prod>
      <prod vendor="cisco" name="telepresence_manager">
        <vers num="1.2.0.0"/>
        <vers num="1.3.2"/>
        <vers num="1.4.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.2"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_software">
        <vers num="1.2.3"/>
        <vers num="1.3.2"/>
        <vers num="1.4.7"/>
        <vers num="1.5.1"/>
        <vers num="1.5.10"/>
        <vers num="1.5.11"/>
        <vers num="1.5.12"/>
        <vers num="1.5.13"/>
        <vers num="1.5.3"/>
        <vers num="1.6.0"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.6.5"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.8"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_1300_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3000">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_3200_series">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_system_500_series">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0380" published="2011-02-25" name="CVE-2011-0380" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65618" source="XF">telepresence-soap-security-bypass(65618)</ref>
      <ref url="http://www.securitytracker.com/id?1025111" source="SECTRACK">1025111</ref>
      <ref url="http://www.securityfocus.com/bid/46526" source="BID">46526</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_manager">
        <vers num="1.2.0.0"/>
        <vers num="1.3.2"/>
        <vers num="1.4.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.0"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0381" published="2011-02-25" name="CVE-2011-0381" modified="2011-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf97085.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65619" source="XF">telepresence-manager-rmi-command-exec(65619)</ref>
      <ref url="http://www.securitytracker.com/id?1025111" source="SECTRACK">1025111</ref>
      <ref url="http://www.securityfocus.com/bid/46526" source="BID">46526</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Manager</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_manager">
        <vers num="1.2.0.0"/>
        <vers num="1.3.2"/>
        <vers num="1.4.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.6.0"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0382" published="2011-02-25" name="CVE-2011-0382" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securityfocus.com/bid/46522" source="BID">46522</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0383" published="2011-02-25" name="CVE-2011-0383" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65602" source="XF">telepresence-java-unauth-access(65602)</ref>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46519" source="BID">46519</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0384" published="2011-02-25" name="CVE-2011-0384" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65620" source="XF">cisco-switch-java-unauth-access(65620)</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46520" source="BID">46520</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0385" published="2011-02-25" name="CVE-2011-0385" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitrary files, and possibly execute arbitrary code, via a crafted request, aka Bug IDs CSCth85786 and CSCth61065.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65604" source="XF">telepresence-interface-file-upload(65604)</ref>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0386" published="2011-02-25" name="CVE-2011-0386" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overwrite files and consequently execute arbitrary code via a malformed request, aka Bug ID CSCti50739.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65605" source="XF">telepresence-xmlrpc-file-overwrite(65605)</ref>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securityfocus.com/bid/46522" source="BID">46522</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.7.0"/>
        <vers num="1.7.1"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0387" published="2011-02-25" name="CVE-2011-0387" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:C)" CVSS_score="8.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="8.0" CVSS_base_score="8.0">
    <desc>
      <descript source="cve">The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote authenticated users to cause a denial of service or have unspecified other impact via vectors involving access to a servlet, aka Bug ID CSCtf97164.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65621" source="XF">cisco-multipoint-interface-dos(65621)</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46520" source="BID">46520</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0388" published="2011-02-25" name="CVE-2011-0388" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46523" source="BID">46523</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0389" published="2011-02-25" name="CVE-2011-0389" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allow remote attackers to cause a denial of service (process crash) via a crafted Real-Time Transport Control Protocol (RTCP) UDP packet, aka Bug ID CSCth60993.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65622" source="XF">cisco-multipoint-rtpc-dos(65622)</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46520" source="BID">46520</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0390" published="2011-02-25" name="CVE-2011-0390" modified="2011-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka Bug ID CSCtj44534.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65623" source="XF">telepresence-multipoint-xmlrpc-dos(65623)</ref>
      <ref url="http://www.securitytracker.com/id?1025113" source="SECTRACK">1025113</ref>
      <ref url="http://www.securityfocus.com/bid/46520" source="BID">46520</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14e.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_multipoint_switch_software">
        <vers num="1.0.4.0"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5.6"/>
        <vers num="1.6.0"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.4"/>
        <vers num="1.7.0"/>
      </prod>
      <prod vendor="cisco" name="telepresence_multipoint_switch">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0391" published="2011-02-25" name="CVE-2011-0391" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65607" source="XF">telepresence-adhoc-dos(65607)</ref>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securityfocus.com/bid/46522" source="BID">46522</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0392" published="2011-02-25" name="CVE-2011-0392" modified="2011-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65609" source="XF">telepresence-xmlrpc-security-bypass(65609)</ref>
      <ref url="http://www.securitytracker.com/id?1025114" source="SECTRACK">1025114</ref>
      <ref url="http://www.securityfocus.com/bid/46522" source="BID">46522</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco TelePresence Recording Server</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="telepresence_recording_server_software">
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
      </prod>
      <prod vendor="cisco" name="telepresence_recording_server">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0393" published="2011-02-25" name="CVE-2011-0393" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.12), 7.1 and 7.2 before 7.2(5.2), 8.0 before 8.0(5.21), 8.1 before 8.1(2.49), 8.2 before 8.2(3.6), and 8.3 before 8.3(2.7) and Cisco PIX Security Appliances 500 series devices, when transparent firewall mode is configured but IPv6 is not configured, allow remote attackers to cause a denial of service (packet buffer exhaustion and device outage) via IPv6 traffic, aka Bug ID CSCtj04707.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65589" source="XF">asa-packet-buffer-dos(65589)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0493" source="VUPEN">ADV-2011-0493</ref>
      <ref url="http://www.securitytracker.com/id?1025108" source="SECTRACK">1025108</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/43488" source="SECUNIA">43488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="7.0"/>
        <vers num="7.0(0)"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(4)"/>
        <vers num="7.0(5)"/>
        <vers num="7.0(5.2)"/>
        <vers num="7.0(6.7)"/>
        <vers num="7.0.1"/>
        <vers num="7.0.1.4"/>
        <vers num="7.0.2"/>
        <vers num="7.0.4"/>
        <vers num="7.0.4.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8" edition="interim"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2.27)"/>
        <vers num="7.1(2.48)"/>
        <vers num="7.1(2.49)"/>
        <vers num="7.1(2.5)"/>
        <vers num="7.1(5)"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.2"/>
        <vers num="7.2(1)"/>
        <vers num="7.2(1.22)"/>
        <vers num="7.2(2)"/>
        <vers num="7.2(2.10)"/>
        <vers num="7.2(2.14)"/>
        <vers num="7.2(2.15)"/>
        <vers num="7.2(2.16)"/>
        <vers num="7.2(2.17)"/>
        <vers num="7.2(2.18)"/>
        <vers num="7.2(2.19)"/>
        <vers num="7.2(2.48)"/>
        <vers num="7.2(2.5)"/>
        <vers num="7.2(2.7)"/>
        <vers num="7.2(2.8)"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="8.0"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers prev="1" num="8.3(1)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0394" published="2011-02-25" name="CVE-2011-0394" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 before 7.0(8.11), 7.1 and 7.2 before 7.2(5.1), 8.0 before 8.0(5.19), 8.1 before 8.1(2.47), 8.2 before 8.2(2.19), and 8.3 before 8.3(1.8); Cisco PIX Security Appliances 500 series devices; and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(20), 3.2 before 3.2(20), 4.0 before 4.0(15), and 4.1 before 4.1(5) allow remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug IDs CSCtg69457 and CSCtl84952.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65593" source="XF">cisco-fwsm-sccp-dos(65593)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0494" source="VUPEN">ADV-2011-0494</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0493" source="VUPEN">ADV-2011-0493</ref>
      <ref url="http://www.securitytracker.com/id?1025109" source="SECTRACK">1025109</ref>
      <ref url="http://www.securitytracker.com/id?1025108" source="SECTRACK">1025108</ref>
      <ref url="http://www.securityfocus.com/bid/46518" source="BID">46518</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e148.shtml" source="CISCO" adv="1">20110223 Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/43488" source="SECUNIA">43488</ref>
      <ref url="http://secunia.com/advisories/43453" source="SECUNIA">43453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="7.0"/>
        <vers num="7.0(0)"/>
        <vers num="7.0(2)"/>
        <vers num="7.0(4)"/>
        <vers num="7.0(5)"/>
        <vers num="7.0(5.2)"/>
        <vers num="7.0(6.7)"/>
        <vers num="7.0.1"/>
        <vers num="7.0.1.4"/>
        <vers num="7.0.2"/>
        <vers num="7.0.4"/>
        <vers num="7.0.4.3"/>
        <vers num="7.0.5"/>
        <vers num="7.0.6"/>
        <vers num="7.0.7"/>
        <vers num="7.0.8" edition="interim"/>
        <vers num="7.1"/>
        <vers num="7.1(2)"/>
        <vers num="7.1(2.27)"/>
        <vers num="7.1(2.48)"/>
        <vers num="7.1(2.49)"/>
        <vers num="7.1(2.5)"/>
        <vers num="7.1(5)"/>
        <vers num="7.1.1"/>
        <vers num="7.1.2"/>
        <vers num="7.2"/>
        <vers num="7.2(1)"/>
        <vers num="7.2(1.22)"/>
        <vers num="7.2(2)"/>
        <vers num="7.2(2.10)"/>
        <vers num="7.2(2.14)"/>
        <vers num="7.2(2.15)"/>
        <vers num="7.2(2.16)"/>
        <vers num="7.2(2.17)"/>
        <vers num="7.2(2.18)"/>
        <vers num="7.2(2.19)"/>
        <vers num="7.2(2.48)"/>
        <vers num="7.2(2.5)"/>
        <vers num="7.2(2.7)"/>
        <vers num="7.2(2.8)"/>
        <vers num="7.2.1"/>
        <vers num="7.2.2"/>
        <vers num="7.2.3"/>
        <vers num="7.2.4"/>
        <vers num="7.2.5"/>
        <vers num="8.0"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.2(3)"/>
        <vers num="8.2(3.9)"/>
        <vers num="8.2(4)"/>
        <vers num="8.2.1"/>
        <vers num="8.2.2" edition="interim"/>
        <vers prev="1" num="8.3(1)"/>
      </prod>
      <prod vendor="cisco" name="5500_series_adaptive_security_appliance">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.1(1)"/>
        <vers num="8.1(2)"/>
      </prod>
      <prod vendor="cisco" name="firewall_services_module_software">
        <vers num="3.1"/>
        <vers num="3.1(16)"/>
        <vers num="3.1(17)"/>
        <vers num="3.1(18)"/>
        <vers num="3.1(19)"/>
        <vers num="3.1(5)"/>
        <vers num="3.1(6)"/>
        <vers num="3.2"/>
        <vers num="3.2(1)"/>
        <vers num="3.2(13)"/>
        <vers num="3.2(14)"/>
        <vers num="3.2(16)"/>
        <vers num="3.2(2)"/>
        <vers num="3.2(3)"/>
        <vers num="4.0"/>
        <vers num="4.0(10)"/>
        <vers num="4.0(11)"/>
        <vers num="4.0(12)"/>
        <vers num="4.0(13)"/>
        <vers num="4.0(14)"/>
        <vers num="4.0(4)"/>
        <vers num="4.0(6)"/>
        <vers num="4.0(7)"/>
        <vers num="4.0(8)"/>
        <vers num="4.1"/>
        <vers num="4.1(1)"/>
        <vers num="4.1(2)"/>
        <vers num="4.1(3)"/>
        <vers num="4.1(4)"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0395" published="2011-02-25" name="CVE-2011-0395" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attackers to cause a denial of service (device reload) via a RIP update, aka Bug ID CSCtg66583.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65590" source="XF">asa-rip-dos(65590)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0493" source="VUPEN">ADV-2011-0493</ref>
      <ref url="http://www.securitytracker.com/id?1025108" source="SECTRACK">1025108</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/43488" source="SECUNIA">43488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.3(1)"/>
      </prod>
      <prod vendor="cisco" name="asa_5500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5505">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5510">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5520">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5540">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5550">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5580">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_501">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_506e">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_506">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_515">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_520">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_525">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_535">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.1(1)"/>
        <vers num="8.1(2)"/>
        <vers num="8.2"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2011-0396" published="2011-02-25" name="CVE-2011-0396" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/65591" source="XF">asa-ca-unauth-access(65591)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0493" source="VUPEN">ADV-2011-0493</ref>
      <ref url="http://www.securitytracker.com/id?1025108" source="SECTRACK">1025108</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtml" source="CISCO" adv="1">20110223 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</ref>
      <ref url="http://secunia.com/advisories/43488" source="SECUNIA">43488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_software">
        <vers num="8.3(1)"/>
      </prod>
      <prod vendor="cisco" name="asa_5500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5505">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5510">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5520">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5540">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5550">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="asa_5580">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_500">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_501">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_506e">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_506">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_515">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_520">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_525">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="pix_firewall_535">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.0"/>
        <vers num="8.0(2)"/>
        <vers num="8.0(3)"/>
        <vers num="8.0(4)"/>
        <vers num="8.0(5)"/>
        <vers num="8.1(1)"/>
        <vers num="8.1(2)"/>
        <vers num="8.2"/>
        <vers num="8.2(1)"/>
        <vers num="8.2(2)"/>
        <vers num="8.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2011-0398" published="2011-01-10" name="CVE-2011-0398" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass intended geolocation and logging functionality via (1) use of a private (aka RFC 1918) address behind a proxy server or (2) spoofing of the X-Forward